CVE-2025-56807: XSS
A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in the admin dashboard when creating new folders.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56807?
CVE-2025-56807 is classified as a medium severity vulnerability due to its ability to allow stored cross-site scripting (XSS).
How do I fix CVE-2025-56807?
To fix CVE-2025-56807, ensure that user input is properly sanitized and validated in the file explorer to prevent JavaScript payloads from being stored.
Who is affected by CVE-2025-56807?
CVE-2025-56807 affects users of FairSketch RISE Ultimate Project Manager & CRM version 3.9.4 who have admin access.
What type of vulnerability is CVE-2025-56807?
CVE-2025-56807 is a stored cross-site scripting (XSS) vulnerability that can be exploited through the admin dashboard.
Can CVE-2025-56807 be exploited remotely?
Yes, CVE-2025-56807 can be exploited remotely by an attacker with access to the admin dashboard.