CVE-2014-5441: Fatfreecrm Fat Free CRM

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) create or (b) edit user action.

Affected products

  • Fatfreecrm Fat Free CRM: up to and including 0.13.0; version 0.11.1 only; version 0.11.2 only; version 0.11.4 only; version 0.12.0 only; version 0.12.1 only

Published 2014-09-12. Last modified 2026-06-17.