Fairsketch RISE CRM Framework HTML Injection Vulnerability
Vulnerability
A HTML injection vulnerability exists in Fairsketch's RISE CRM Framework version 3.8.1. This vulnerability allows for HTML code injection due to inadequate validation of user inputs. The issue can be exploited by sending a POST request with malicious HTML in the 'title' parameter to the '/tickets/save' endpoint.
Impact
Exploitation of this vulnerability allows for HTML injection, which could be used to execute scripts in the context of the user.
Remediation
Users can upgrade to Fairsketch RISE CRM Framework version 3.9 to address this vulnerability.
Added: Nov 11, 2025, 1:17 PM
Updated: Nov 11, 2025, 1:17 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.7exploitability
5.0remediation
7.7relevance
0.9threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
