Junglewise Threat Intelligence

CVE-2025-60378: Fairsketch RISE Ultimate Project Manager & CRM stored HTML injection

CVE-2025-60378 · Severity: high · CVSS 8.1 · Published 2025-10-10

Technologies: Fairsketch Rise Ultimate Project Manager, Fairsketch RISE Ultimate Project Manager & CRM. Vendors: Fairsketch.

Executive brief

RISE Ultimate Project Manager & CRM, a platform used for managing business operations and client communications, contains a security flaw that allows logged-in users to insert malicious code into invoices and messages. This code is then automatically distributed to other employees or clients through emails, PDF documents, and internal chat systems. An attacker could use this to steal login credentials, perform phishing attacks, or disrupt business operations by sending fraudulent communications.

Technical details

A stored HTML injection vulnerability (classified under CWE-79) exists in RISE Ultimate Project Manager & CRM versions prior to 3.9.4. The flaw resides in the invoice and messaging modules, where the application fails to properly neutralize user-supplied input before storing it. An authenticated attacker can inject arbitrary HTML tags that are subsequently rendered in various contexts, including the web-based chat module, generated PDF invoices, and outgoing notification emails. This can be leveraged for credential theft, phishing, or business email compromise. The risk is further amplified by the platform's automated recurring invoice feature, which can distribute the malicious payload to multiple recipients without further attacker interaction. The issue is addressed in version 3.9.4.

Affected products

  • Fairsketch RISE Ultimate Project Manager & CRM < 3.9.4

Timeline

  • 2025-10-10: advisory
  • 2025-11-17: patched: NVD record indicates versions up to 3.9.4 are affected; fix available in 3.9.4.

References

Related threats