Junglewise Threat Intelligence

CVE-2025-56807: FairSketch RISE Ultimate Project Manager & CRM stored XSS in File Manager

CVE-2025-56807 · Severity: medium · CVSS 6.1 · Published 2025-09-29

Technologies: Fairsketch Rise Ultimate Project Manager, Fairsketch RISE Ultimate Project Manager & CRM. Vendors: Fairsketch.

Executive brief

FairSketch RISE Ultimate Project Manager & CRM, a tool used for managing business projects and customer relationships, contains a security flaw in its file management system. An attacker with folder-creation permissions can plant malicious scripts that execute when other users, including administrators, view the file explorer. This could lead to unauthorized access to sensitive business data or the hijacking of user sessions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the File Manager component of FairSketch RISE Ultimate Project Manager & CRM version 3.9.4. The flaw is located in the 'title' parameter of the folder creation request (POST /index.php/clients/save_folder), which fails to sufficiently sanitize user input. An attacker with permissions to create folders can inject an HTML/JavaScript payload that is stored in the database. When any user, including an administrator, views the folder list in the File Manager, the payload executes in their browser context, potentially allowing for session hijacking or data exfiltration. While initial reports suggested this was limited to administrators, further analysis indicates any user with folder-creation privileges can exploit this.

Affected products

  • FairSketch RISE Ultimate Project Manager & CRM 3.9.4

Timeline

  • 2025-07-22: other: Vendor acknowledged the vulnerability report
  • 2025-09-29: advisory: NVD publication date

References

Related threats