HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fairsketch
Fairsketch rise Crm Framework |
|
| Vendors & Products |
Fairsketch
Fairsketch rise Crm Framework |
Tue, 11 Nov 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'. | |
| Title | Multiple vulnerabilities in Fairsketch's RISE CRM Framework | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-11-11T12:17:41.493Z
Updated: 2025-11-14T19:26:44.352Z
Reserved: 2025-04-16T09:09:37.997Z
Link: CVE-2025-41104
Updated: 2025-11-14T19:26:41.112Z
Status : Awaiting Analysis
Published: 2025-11-11T13:15:44.723
Modified: 2025-11-12T16:19:34.210
Link: CVE-2025-41104
No data.