FairSketch Rise CRM Insecure Permissions Vulnerability

Vulnerability

A vulnerability exists in FairSketch Rise Ultimate Project Manager & CRM version 3.9.4, allowing remote authenticated users to exploit insecure permissions. Due to inadequate authorization checks in the ticketing and commenting API, users can append comments or upload attachments to tickets without the necessary view or edit rights.

Impact

Exploitation of this vulnerability enables standard users to interact with support tickets inappropriately, potentially misleading other users by impersonating administrative or helpdesk roles.

Reproduction

To reproduce this vulnerability, a standard user must send a POST request to the '/tickets/save_comment' endpoint, including a 'ticket_id' parameter that corresponds to a ticket not assigned to them. This can be done by intercepting and modifying the request to change the 'ticket_id' value, allowing comments to be added to tickets of other users.

Added: Nov 3, 2025, 9:23 PM
Updated: Nov 3, 2025, 9:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
0.6
exploitability
6.2
remediation
0.0
relevance
0.9
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.