PT-2025-41567 · Rise · Rise Ultimate Project Manager

Ajansha

·

Published

2025-10-10

·

Updated

2025-11-17

·

CVE-2025-60378

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions RISE Ultimate Project Manager & CRM (affected versions not specified)
Description An issue exists in RISE Ultimate Project Manager & CRM that allows authenticated users to inject arbitrary HTML into invoices and messages. This injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, potentially enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging can amplify the risk by distributing malicious content to multiple recipients. The vulnerability allows injection of arbitrary HTML content into invoices and messaging modules.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60378

Affected Products

Rise Ultimate Project Manager