CVE-2026-71368: Medium severity F-RevoCRM vulnerability
Published Aug 20, 2026
·Updated
F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
Affected Software
1 affected component
F-RevoCRM
Event History
Aug 20, 2026
CVE Published
via MITRE·06:28 AM
Data Sourced
via MITRE·06:28 AM
DescriptionSeverity
Frequently Asked Questions
1
Does an attacker need an account or prior privileges in F-RevoCRM?
No. The vulnerability is rated PR:N, indicating that the attacker does not need privileges before attempting exploitation. Exploitation does require a logged-in user to view a crafted page.
2
What level of user interaction is needed for exploitation?
User interaction is required. A logged-in F-RevoCRM user must view attacker-crafted content or a crafted page.
3
What is the expected security impact?
The reported impact is low confidentiality and low integrity impact, with no availability impact. Successful exploitation may cause unintended operations in the affected product.