HTML Injection Vulnerability in Fairsketch's RISE CRM Framework
CVE-2025-41106
5.1MEDIUM
What is CVE-2025-41106?
An HTML injection vulnerability exists in Fairsketch's RISE CRM Framework v3.8.1 due to inadequate validation of user inputs. This issue arises when a malicious actor sends a crafted POST request, specifically targeting the 'first_name' parameter in the '/clients/save_contact/' endpoint. The lack of proper sanitization allows for the injection of arbitrary HTML code, which could lead to unauthorized content manipulation and potential phishing attacks.
Affected Version(s)
RISE CRM Framework prior to 3.9
