CVE-2025-56807
MEDIUMFairSketch RISE Ultimate Project Manager & CRM 3.9.4 - Stored Cross-Site Scripting via Admin Dashboard File Explorer
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-56807. PoCs published by aqwainfosec.
AI-analyzed exploit summary This repository provides a detailed proof-of-concept for a stored XSS vulnerability in FairSketch RISE Ultimate Project Manager & CRM (v3.9.4). The exploit leverages insufficient input sanitization in the folder title parameter to inject and execute arbitrary JavaScript.
Description
A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in the admin dashboard when creating new folders.
Exploits (1)
This repository provides a detailed proof-of-concept for a stored XSS vulnerability in FairSketch RISE Ultimate Project Manager & CRM (v3.9.4). The exploit leverages insufficient input sanitization in the folder title parameter to inject and execute arbitrary JavaScript.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N