Fairsketch RISE CRM Framework HTML Injection Vulnerability

Vulnerability

A HTML injection vulnerability exists in Fairsketch's RISE CRM Framework version 3.8.1. This vulnerability arises from inadequate validation of user inputs, allowing for HTML code injection. The issue can be exploited by sending a POST request with malicious HTML in the 'title' parameter to the '/projects/save' endpoint.

Impact

Exploitation of this vulnerability allows for HTML injection, where an attacker can inject malicious HTML that could be executed in the context of the user's browser.

Remediation

Users can upgrade to Fairsketch RISE CRM Framework version 3.9 to address this vulnerability.

Added: Nov 11, 2025, 12:18 PM
Updated: Nov 11, 2025, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.0
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.