Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fat Free CRM 跨站请求伪造漏洞
Vulnerability Description
Fat Free CRM是一套开源的基于Ruby on Rails的客户关系管理平台。该平台包含团队协作、客户管理、联系人列表、客户跟踪等模块。 Fat Free CRM 0.13.5及之前版本中存在安全漏洞。远程攻击者可通过发送不带‘authenticity_token’参数的请求利用该漏洞实施跨站请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A