F-RevoCRM XSS Flaw CVE-2026-71368 Puts Logged-In Users at Risk
A medium-severity cross-site scripting vulnerability, tracked as CVE-2026-71368, has been disclosed in F-RevoCRM versions 7.3.0 through 8.0.3, with a fix available in version 8.0.4. The flaw, published by JVN on August 17, 2026, allows an attacker to craft a malicious URL that, when opened by a logged-in user, executes arbitrary JavaScript within the CRM's origin. This can result in unintended CRM operations or the theft of session information using the victim's existing privileges. No authentication is required from the attacker, but the attack does depend on a valid user session and some form of user interaction, such as clicking a link sent via email or chat. Users are advised to update to version 8.0.4 immediately and to avoid opening untrusted links while logged in to the platform.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in