Impact
FairSketch Rise CRM 3.9.6 contains a stored cross‑site scripting flaw that lets an authenticated administrator write arbitrary JavaScript into an item’s title. The script is stored on the server and executed in the browser of any customer who views the store page, enabling attackers to hijack user sessions, take over accounts, and launch phishing attacks.
Affected Systems
The vulnerability affects FairSketch Rise CRM version 3.9.6. No other versions or additional vendors are listed.
Risk and Exploitability
An attacker must first obtain administrator privileges in the system to inject malicious code; however, once the payload is stored, it affects all subsequent users who visit the compromised store page. Because the flaw is stored XSS, it can be abused without community exploits yet, and the EPSS score is not available while the vulnerability is not listed in the CISA KEV catalog. The lack of public exploitation data does not diminish the inherent risk, as the internal privilege requirement does not preclude exploitation by legitimate administrators or compromised accounts.
OpenCVE Enrichment