CVE-2014-5441: Fatfreecrm Fat Free CRM
Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) create or (b) edit user action.
Affected products
- Fatfreecrm Fat Free CRM: up to and including 0.13.0; version 0.11.1 only; version 0.11.2 only; version 0.11.4 only; version 0.12.0 only; version 0.12.1 only
Published 2014-09-12. Last modified 2026-06-17.