HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
These vulnerabilities have been fixed by the Fairsketch team in version 3.9.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fairsketch
Fairsketch rise Crm Framework |
|
| Vendors & Products |
Fairsketch
Fairsketch rise Crm Framework |
Tue, 11 Nov 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'. | |
| Title | Multiple vulnerabilities in Fairsketch's RISE CRM Framework | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-11-11T11:57:40.402Z
Reserved: 2025-04-16T09:09:37.997Z
Link: CVE-2025-41102
No data.
Status : Awaiting Analysis
Published: 2025-11-11T12:15:34.713
Modified: 2025-11-12T16:19:34.210
Link: CVE-2025-41102
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:42:32Z