Published: 2026/08/17  Last Updated: 2026/08/17

Information from Thinkingreed Inc.

Vulnerability ID:JVN#58692577
Title:F-RevoCRM vulnerable to cross-site scripting
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

A vulnerability has been discovered in F-RevoCRM version 7.x and later (7.x and 8.x).

■ Affected Applications
All versions from F-RevoCRM 7.3.0 through F-RevoCRM 8.0.3 (i.e., all 7.x and later releases)

■ Overview
A cross-site scripting vulnerability may allow arbitrary scripts to be executed in the web browser of a user logged in to F-RevoCRM.

■ Potential Impact
If a user accesses a specially crafted URL, arbitrary scripts may be executed in the web browser of that user while logged in to the site.
As a result, unintended operations may be performed, or session information may be stolen and the account used illegitimately.

■ Severity
CVSS v3.0 Base Score 6.1
 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0 Base Score 5.1
 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

■ Workarounds
This vulnerability is only effective while the user is logged in to F-RevoCRM. Therefore, it can be avoided by logging out of F-RevoCRM when visiting untrusted external sites, or by using a separate browser for such sites.
Restricting access to inappropriate sites via a proxy server or similar measures can also be expected to mitigate the impact.

■ Countermeasures
Please update to F-RevoCRM 8.0.4.
For details on upgrading, please refer to the Readme included with the program published on GitHub.
https://github.com/thinkingreed-inc/F-RevoCRM/releases/tag/v8.0.4

In addition, customers who have a support contract with Thinking Reed have already had an individual patch applied, so no further action is required on your part.