Executive brief
F-RevoCRM is a customer relationship management (CRM) system that helps businesses manage client interactions and sales processes. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious code that executes in the browsers of logged-in users, potentially enabling unauthorized actions, data theft, or session hijacking when users visit a crafted page.
Technical details
F-RevoCRM versions 7.3.0 through 8.0.3 contain a reflected or stored cross-site scripting (CWE-79) vulnerability due to insufficient input validation or output encoding. The vulnerability requires user interaction (a user must visit a crafted page) but no authentication from the attacker, with network accessibility. When a logged-in user views the malicious page, attacker-controlled JavaScript executes in the user's browser within the application context, potentially allowing session hijacking, unauthorized operations, or data exfiltration. The vendor has been notified and patching information is available from the developer; users should update to the latest version.
Affected products
- Thinkingreed Inc. F-RevoCRM 7.3.0 through 8.0.3
Timeline
- 2026-08-17: disclosed
- 2026-08-20: advisory