Fairsketch RISE CRM Framework HTML Injection Vulnerability
Vulnerability
A HTML injection vulnerability exists in Fairsketch's RISE CRM Framework version 3.8.1. This vulnerability arises from inadequate validation of user inputs, allowing for HTML code injection. The issue can be exploited by sending a POST request with malicious HTML in the 'first_name' parameter to the '/clients/save_contact/' endpoint.
Impact
Exploitation of this vulnerability allows for HTML injection, which could be used to manipulate the application's content or behavior, potentially leading to cross-site scripting (XSS) attacks.
Remediation
Users can upgrade to Fairsketch RISE CRM Framework version 3.9 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
