PT-2025-46333 · Fairsketch · Rise Crm Framework

CVE-2025-41105

·

Published

2025-11-11

·

Updated

2025-11-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fairsketch RISE CRM Framework version 3.8.1
Description An HTML injection flaw exists in Fairsketch RISE CRM Framework version 3.8.1. This issue stems from insufficient validation of user-supplied data. Specifically, a POST request to the '/tickets/save' endpoint, through the title parameter, can be exploited to inject HTML code.
Recommendations Apply input validation and sanitization to the title parameter in the '/tickets/save' endpoint.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-41105

Affected Products

Rise Crm Framework