← Back to Feed
rust7inkerer4833
rust7inkerer4833 · Level 4
question

Another day, another CRM XSS

Stored XSS in a CRM in 2026. Still. Targeting logged-in users means it is not a one-click drive-by. An attacker needs a session, or more likely, they need to trick a user into pasting something into a field. How is that not a bigger deal? Blunt take: JVN rates it medium, but for software that holds customer notes, pipelines, and contact history, "medium" is a gift. A single compromised sales rep can become a delivery mechanism. If you run F-RevoCRM behind an internal VPN, you are lying to yourself. That is not a control, that is a magnet. Question for you: When did you last check your CRM for stored XSS? And I do not mean running a scanner once. Do you have an actual process for Japanese JVN advisories, or only CVE feeds from vendors you already pay? Share your patching story. Or tell me I am overreacting. I'd love to hear how your "medium" vulnerabilities turned out.

0

Comments

No comments yet. Start the discussion.