Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json.
Loading...
Loading...
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json.
January 2, 2014
April 29, 2026
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| fat_free_crm | 0.11.0 ... 0.12.0 (6 versions) | 0.12.1 | — |
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-7224
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.