CVE-2018-1000842 Information
Description
FatFreeCRM version =0.14.1 =0.15.0 =0.15.1 =0.16.0 =0.16.3 =0.17.0 =0.17.2 ==0.18.0 contains a Cross Site Scripting (XSS) vulnerability in commit 6d60bc8ed010c4eda05d6645c64849f415f68d65 that can result in Javascript execution. This attack appear to be exploitable via Content with Javascript payload will be executed on end user browsers when they visit the page. This vulnerability appears to have been fixed in 0.18.1 0.17.3 0.16.4 0.15.2 0.14.2.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/asteinhauser/fat_free_crm/commit/306f940b26ccf3f406665f07bece1229a7a5dcfa https://github.com/asteinhauser/fat_free_crm/issues/1 https://github.com/fatfreecrm/fat_free_crm/wiki/XSS-Vulnerability-282018-10-2729 https://groups.google.com/forum/!topic/fat-free-crm-users/TxsdZXSe7Jc
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: