CVE-2025-41102: Fairsketch Rise Ultimate Project Manager
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'.
Affected products
- Fairsketch Rise Ultimate Project Manager: before 3.9 (fixed in 3.9)
Published 2025-11-11. Last modified 2026-06-17.