PT-2025-46333 · Fairsketch · Rise Crm Framework

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-41105

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fairsketch RISE CRM Framework version 3.8.1
Description An HTML injection flaw exists in Fairsketch RISE CRM Framework version 3.8.1. This issue stems from insufficient validation of user-supplied data. Specifically, a POST request to the '/tickets/save' endpoint, through the title parameter, can be exploited to inject HTML code.
Recommendations Apply input validation and sanitization to the title parameter in the '/tickets/save' endpoint.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-41105

Affected Products

Rise Crm Framework