CVE-2018-20975

Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fatfreecrm:fat_free_crm:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:02

Type Values Removed Values Added
References () https://github.com/fatfreecrm/fat_free_crm/commit/6d60bc8ed010c4eda05d6645c64849f415f68d65 - Patch, Third Party Advisory () https://github.com/fatfreecrm/fat_free_crm/commit/6d60bc8ed010c4eda05d6645c64849f415f68d65 - Patch, Third Party Advisory
References () https://github.com/fatfreecrm/fat_free_crm/compare/v0.17.3...v0.18.1 - Patch, Third Party Advisory () https://github.com/fatfreecrm/fat_free_crm/compare/v0.17.3...v0.18.1 - Patch, Third Party Advisory
References () https://github.com/fatfreecrm/fat_free_crm/releases/tag/v0.18.1 - Release Notes () https://github.com/fatfreecrm/fat_free_crm/releases/tag/v0.18.1 - Release Notes

Information

Published : 2019-08-20 13:15

Updated : 2024-11-21 04:02


NVD link : CVE-2018-20975

Mitre link : CVE-2018-20975

CVE.ORG link : CVE-2018-20975


JSON object : View

Products Affected

fatfreecrm

  • fat_free_crm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')