Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Nov 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fairsketch:rise_ultimate_project_manager:3.9.4:*:*:*:*:*:*:* |
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fairsketch
Fairsketch rise Ultimate Project Manager |
|
| Vendors & Products |
Fairsketch
Fairsketch rise Ultimate Project Manager |
Mon, 03 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Mon, 03 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T20:48:19.963Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63293
Updated: 2025-11-03T20:47:20.618Z
Status : Analyzed
Published: 2025-11-03T21:19:38.307
Modified: 2025-11-14T18:32:13.647
Link: CVE-2025-63293
No data.
OpenCVE Enrichment
Updated: 2025-11-04T16:36:02Z