CVE-2019-6036: F-Revocrm

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected products

  • F-Revocrm F-Revocrm: from 6.0, before 6.5 (fixed in 6.5); version 6.5 only

Published 2020-01-27. Last modified 2026-06-17.