Medium
CVSS 5.0
Overview
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json.
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows re...
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: