{"id":71387,"date":"2025-10-10T18:46:05","date_gmt":"2025-10-10T15:16:05","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-60378-rise-ultimate-project-manager-crm-stored-html-injection\/"},"modified":"2025-10-10T18:46:05","modified_gmt":"2025-10-10T15:16:05","slug":"cve-2025-60378-rise-ultimate-project-manager-crm-stored-html-injection","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-60378-rise-ultimate-project-manager-crm-stored-html-injection\/","title":{"rendered":"CVE-2025-60378 &#8211; &#8220;RISE Ultimate Project Manager &amp; CRM Stored HTML Injection&#8221;"},"content":{"rendered":"<p>CVE ID : CVE-2025-60378<\/p>\n<p>Published :  Oct. 10, 2025, 3:16 p.m. | 1\u00a0hour, 22\u00a0minutes ago<\/p>\n<p>Description : Stored HTML injection in RISE Ultimate Project Manager &amp; CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging\/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients.<\/p>\n<p>Severity: 8.1 | HIGH<\/p>\n<p>Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-60378 Published : Oct. 10, 2025, 3:16 p.m. | 1\u00a0hour, 22\u00a0minutes ago Description : Stored HTML injection in RISE Ultimate Project Manager &amp; CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging\/chat modules sent to clients or team members, enabling phishing, &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-71387","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/71387","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=71387"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/71387\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=71387"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=71387"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=71387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}