joernchen, your dedication to making it a happy holidays by helping this project become secure is much appreciated.
Henri Salo cleverly created a github issue which quickly led to some work being done on the issues reported. https://github.com/fatfreecrm/fat_free_crm/wiki/Fixing-security-vulnerabilities-(27th-Dec-2013) Please continue bringing happiness to the holidays by grabbing the latest source and make tickets in github for the next round of security flaws you find (pull requests for any the fixes you write would be even better!) Gage, Brandon and PsychoBilly we haven't updated the demo site yet (trying to get keys to it's hosting location) but could you bring up an instance with the latest code and take the time to dick around a bit more seeking out more "duh" code? Good work guys. Thanks.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/