CVE-2025-63293
BaseFortify
Publication date: 2025-11-03
Last updated on: 2025-11-14
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fairsketch | rise_ultimate_project_manager | 3.9.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
FairSketch Rise Ultimate Project Manager & CRM 3.9.4 has a vulnerability called Insecure Permissions. This means that a remote authenticated user can add comments or upload attachments to tickets even if they do not have permission to view or edit those tickets. This happens because the system does not properly check if the user is authorized to perform these actions in the ticketing/commenting API.
How can this vulnerability impact me? :
This vulnerability can allow unauthorized users to modify ticket data by appending comments or uploading attachments without proper permissions. This could lead to information tampering, misinformation, or unauthorized data being added to tickets, potentially disrupting workflows or causing confusion.