Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-41106


HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'.


Published

2025-11-11T13:15:45.037

Last Modified

2025-11-17T15:17:21.450

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fairsketch rise_ultimate_project_manager < 3.9 Yes

References