lowVulnerability
GHSA-9pm8-vwc5-w2hm
### Impact Authenticated users can delete emails imported into the system assigned to another user; where the [Email Dropbox](https://github.com/fatfreecrm/fat_free_crm/wiki/Email-Dropbox) is in use. ### Patches Fixed in v0.26.0 ### Workarounds Disable use of email dropbox.
Properties
- ghsa_id
- GHSA-9pm8-vwc5-w2hm
- severity
- low
- summary
- Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
- cve_id
- GHSA-9pm8-vwc5-w2hm
- is_ghsa_only
- true
- ghsa_published
- 2026-04-14T01:07:01Z
- source_url
- https://github.com/advisories/GHSA-9pm8-vwc5-w2hm
- ghsa_updated
- 2026-04-14T01:07:02Z
Related Entities (4)
VULNERABLE_TO (1)
←[Software]rubygems/fat_free_crm
AFFECTS (1)
→[Software]rubygems/fat_free_crm
HAS_WEAKNESS (1)
→[Weakness]Authorization Bypass Through User-Controlled Key
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph