{"id":"CVE-2014-5441","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-5441","summary":"Fat Free CRM subject to Cross-site Scripting","details":"Multiple cross-site scripting (XSS) vulnerabilities in `app/views/layouts/application.html.haml` in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) create or (b) edit user action.","published":"2022-05-17T04:35:23Z","modified":"2024-12-03T06:04:56.546820Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"fat_free_crm","fixedVersion":"0.13.3"}],"fix":{"url":"https://github.com/fatfreecrm/fat_free_crm/commit/95464495f1e3e714d5c295fe621af5d2e0d4238d","label":"fatfreecrm/fat_free_crm@9546449"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-5441"},{"type":"WEB","url":"https://github.com/fatfreecrm/fat_free_crm/commit/95464495f1e3e714d5c295fe621af5d2e0d4238d"},{"type":"PACKAGE","url":"https://github.com/fatfreecrm/fat_free_crm"},{"type":"WEB","url":"https://github.com/fatfreecrm/fat_free_crm/wiki/XSS-vulnerability-%2826th-August-2014%29"},{"type":"WEB","url":"http://packetstormsecurity.com/files/127978/Fatt-Free-CRM-Cross-Site-Scripting.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-03T06:04:56.546820Z"}}