CVE-2025-60378

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/10/2025
Last modified:
17/11/2025

Description

Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fairsketch:rise_ultimate_project_manager:*:*:*:*:*:*:*:* 3.9.4 (excluding)


References to Advisories, Solutions, and Tools