Skip to content

Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID

Low severity GitHub Reviewed Published Apr 12, 2026 in fatfreecrm/fat_free_crm • Updated Apr 14, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts