lowVulnerability

GHSA-9pm8-vwc5-w2hm

### Impact Authenticated users can delete emails imported into the system assigned to another user; where the [Email Dropbox](https://github.com/fatfreecrm/fat_free_crm/wiki/Email-Dropbox) is in use. ### Patches Fixed in v0.26.0 ### Workarounds Disable use of email dropbox.

Properties

ghsa_id
GHSA-9pm8-vwc5-w2hm
severity
low
summary
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
cve_id
GHSA-9pm8-vwc5-w2hm
is_ghsa_only
true
ghsa_published
2026-04-14T01:07:01Z
source_url
https://github.com/advisories/GHSA-9pm8-vwc5-w2hm
ghsa_updated
2026-04-14T01:07:02Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]rubygems/fat_free_crm

AFFECTS (1)

[Software]rubygems/fat_free_crm

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-9pm8-vwc5-w2hm — Ninja Signal Threat Intelligence | Ninja Signal