CVE-2025-41102: Multiple vulnerabilities in Fairsketch's RISE CRM Framework
Published Nov 11, 2025
·Updated
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'.
Affected Software
2 affected components
Fairsketch RISE CRM Framework
Fairsketch Rise Ultimate Project Manager<3.9
Remediation
Information
These vulnerabilities have been fixed by the Fairsketch team in version 3.9.
Event History
Nov 11, 2025
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41102?
CVE-2025-41102 is classified as a high-severity HTML injection vulnerability.
2
How do I fix CVE-2025-41102?
To fix CVE-2025-41102, ensure proper validation and sanitization of user inputs in the 'title' parameter during POST requests.
3
Which versions of Fairsketch RISE CRM Framework are affected by CVE-2025-41102?
CVE-2025-41102 affects Fairsketch's RISE CRM Framework version 3.8.1.
4
What type of attack does CVE-2025-41102 facilitate?
CVE-2025-41102 facilitates HTML injection attacks that may allow attackers to execute malicious scripts.
5
What is the potential impact of CVE-2025-41102?
The potential impact of CVE-2025-41102 includes compromised user sessions, data theft, and defacement of web applications.