Medium severity6.1NVD Advisory· Published Jan 27, 2020· Updated Jun 17, 2026
CVE-2019-6036
CVE-2019-6036
Description
Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:f-revocrm:f-revocrm:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:f-revocrm:f-revocrm:*:*:*:*:*:*:*:*range: >=6.0,<6.5
- cpe:2.3:a:f-revocrm:f-revocrm:6.5:-:*:*:*:*:*:*
- cpe:2.3:a:f-revocrm:f-revocrm:6.5:patch2:*:*:*:*:*:*
- cpe:2.3:a:f-revocrm:f-revocrm:6.5:patch4:*:*:*:*:*:*
- cpe:2.3:a:f-revocrm:f-revocrm:6.5:patch5:*:*:*:*:*:*
- cpe:2.3:a:f-revocrm:f-revocrm:6.5:patch6:*:*:*:*:*:*
- (no CPE)range: 6.0 to 6.5 patch6
- ThinkingReed inc./F-RevoCRMv5Range: 6.0 to F-RevoCRM 6.5 patch6 (version 6 series)
Patches
Vulnerability mechanics
References
2- jvn.jp/en/jp/JVN97325754/index.htmlnvdThird Party Advisory
- f-revocrm.jp/2019/12/9393nvdVendor Advisory
News mentions
0No linked articles in our index yet.