HTML Injection Vulnerability in Fairsketch's RISE CRM Framework
CVE-2025-41102
5.1MEDIUM
What is CVE-2025-41102?
An HTML injection vulnerability has been identified in Fairsketch's RISE CRM Framework version 3.8.1. This flaw arises from inadequate validation of user inputs, allowing attackers to inject malicious HTML code through the 'title' parameter when submitting a POST request to the '/events/save' endpoint. Exploiting this vulnerability can lead to various security issues, including data exposure and manipulation.
Affected Version(s)
RISE CRM Framework prior to 3.9
