Impact
FairSketch Rise CRM version 3.9.CWE-79) that allows an authenticated administrator to embed arbitrary JavaScript into an item’s title. The malicious payload is stored on the server and executed in the browsers of any client user who visits the compromised store page, enabling session hijacking, account takeover, and phishing attacks.
Affected Systems
The vulnerability affects FairSketch Rise CRM version 3.9.6. No other vendors, products, or versions are listed as affected.
Risk and Exploitability
Exploitation requires administrator privileges to inject malicious code, as noted in the description. Once the payload is stored, it automatically executes for any user who visits the compromised store page, regardless of their privilege. The EPSS score of < 1% indicates a low likelihood of exploitation, while the CVSS score of 5.4 represents moderate severity. The vulnerability is not listed in the CISA KEV catalog, but its stored XSS nature permits session hijacking, account takeover, and phishing against all site visitors.
OpenCVE Enrichment