Executive brief
FairSketch Rise Ultimate Project Manager & CRM, a tool used for managing business projects and customer relationships, contains a security flaw in its ticketing system. An authorized user of the system can add comments or upload files to support tickets that they are not supposed to see or edit. This could allow unauthorized individuals to interfere with customer support processes or inject malicious attachments into private project discussions.
Technical details
A missing authorization check (CWE-862) exists within the ticketing and commenting API of FairSketch Rise Ultimate Project Manager & CRM version 3.9.4. A remote authenticated attacker can exploit this by sending crafted requests to the API to append comments or upload attachments to tickets for which they lack the necessary view or edit permissions. The vulnerability stems from the application failing to verify if the requesting user has the appropriate relationship or authorization level for the specific ticket ID being modified. While the attacker cannot necessarily read the existing ticket content through this specific flaw, they can compromise the integrity of the ticket data and potentially use it as a vector for further attacks via malicious attachments.
Affected products
- FairSketch Rise Ultimate Project Manager & CRM 3.9.4
Timeline
- 2025-11-03: disclosed
- 2025-11-03: advisory