HTML Injection Vulnerability in Fairsketch's RISE CRM Framework
CVE-2025-41103
5.1MEDIUM
What is CVE-2025-41103?
An HTML injection vulnerability has been identified in Fairsketch's RISE CRM Framework version 3.8.1. This issue arises from insufficient validation of user inputs, specifically when a POST request is made with the 'reply_message' parameter in the '/messages/reply' endpoint. Attackers can exploit this flaw by injecting malicious HTML code, which can lead to unauthorized content manipulation, potentially compromising the integrity of data and affecting user experience. Proper validation measures are essential to mitigate such vulnerabilities.
Affected Version(s)
RISE CRM Framework prior to 3.9
