CVE-2019-6036

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
27/01/2020
Last modified:
28/01/2020

Description

Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f-revocrm:f-revocrm:*:*:*:*:*:*:*:* 6.0 (including) 6.5 (excluding)
cpe:2.3:a:f-revocrm:f-revocrm:6.5:-:*:*:*:*:*:*
cpe:2.3:a:f-revocrm:f-revocrm:6.5:patch2:*:*:*:*:*:*
cpe:2.3:a:f-revocrm:f-revocrm:6.5:patch4:*:*:*:*:*:*
cpe:2.3:a:f-revocrm:f-revocrm:6.5:patch5:*:*:*:*:*:*
cpe:2.3:a:f-revocrm:f-revocrm:6.5:patch6:*:*:*:*:*:*