File tree Expand file tree Collapse file tree 1 file changed +32
-0
lines changed
Expand file tree Collapse file tree 1 file changed +32
-0
lines changed Original file line number Diff line number Diff line change 1+ ---
2+ gem : fat_free_crm
3+ ghsa : 9pm8-vwc5-w2hm
4+ url : https://github.com/fatfreecrm/fat_free_crm/security/advisories/GHSA-9pm8-vwc5-w2hm
5+ title :
6+ Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated
7+ user can hit this endpoint and delete emails by ID
8+ date : 2026-04-14
9+ description : |
10+ Fat Free CRM has BOLA (Broken Object Level Authorization) in
11+ DELETE /emails/:id - Any authenticated user can hit this
12+ endpoint and delete emails by ID
13+
14+ ### Impact
15+
16+ Authenticated users can delete emails imported into the system
17+ assigned to another user; where the
18+ [Email Dropbox](https://github.com/fatfreecrm/fat_free_crm/wiki/Email-Dropbox)
19+ is in use.
20+
21+ ### Workarounds
22+
23+ Disable use of email dropbox.
24+ cvss_v3 : 2.1
25+ patched_versions :
26+ - " >= 0.26.0"
27+ related :
28+ url :
29+ - https://rubygems.org/gems/fat_free_crm/versions/0.26.0
30+ - https://github.com/fatfreecrm/fat_free_crm/releases/tag/v0.26.0
31+ - https://github.com/fatfreecrm/fat_free_crm/security/advisories/GHSA-9pm8-vwc5-w2hm
32+ - https://github.com/advisories/GHSA-9pm8-vwc5-w2hm
You can’t perform that action at this time.
0 commit comments