CVE-2025-60378
8.1RISE · Ultimate Project Manager & CRM
Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages, facilitating phishing and credential theft.
Executive summary
A stored HTML injection vulnerability in RISE Ultimate Project Manager & CRM allows authenticated attackers to compromise communication channels and conduct phishing attacks against clients or team members.
Vulnerability
This is a stored HTML injection vulnerability that allows an authenticated user to inject malicious content into invoices, PDFs, and messaging modules. The injected payload executes when viewed by recipients, enabling credential harvesting and business email compromise.
Business impact
The ability to inject arbitrary HTML into customer-facing invoices and internal messages poses a severe risk to organizational integrity and client trust. With a CVSS score of 8.1, this high-severity flaw can be leveraged to facilitate sophisticated phishing campaigns or session hijacking, potentially leading to unauthorized access to sensitive project data and financial information.
Remediation
Immediate Action: Contact the vendor to obtain the latest security patch or update for your installation of RISE Ultimate Project Manager & CRM. In the absence of a direct patch, restrict access to invoice and messaging modules to trusted administrative users only.
Proactive Monitoring: Review audit logs for suspicious activity within the CRM, specifically monitoring for unusual HTML tags or scripts embedded in invoice templates or message history.
Compensating Controls: Implement a Web Application Firewall (WAF) with strict input validation rules to block common HTML injection patterns and malicious script vectors from being stored in the database.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept repository exists on GitHub (https://github.com/ajansha/CVE-2025-60378).
Analyst recommendation
Given the availability of a public proof-of-concept and the high-severity CVSS score, administrators must prioritize addressing this vulnerability. Apply all available vendor updates immediately to prevent unauthorized modification of business communications and to protect the integrity of client-facing documentation.