CVE-2026-36392 Details
Description
FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's title, which is stored server-side and executed in the browser of any client user who visits the store page, enabling session hijacking, account takeover, and phishing.
A stored cross-site scripting vulnerability has been identified in FairSketch Rise CRM versions through 3.9.6. This issue allows authenticated administrators to inject arbitrary JavaScript into an item's title. The injected script is executed in the browsers of client users who visit the store page, potentially leading to session hijacking, account takeover, and phishing attacks.
Users are advised to upgrade to FairSketch Rise CRM version 4.0 or later, where this vulnerability has been fixed by adding input validation to the affected title field.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/moksh-nfsu/CVE-2026-36392 | CISA-ADP | ExploitTechnical Description |
| https://github.com/moksh-nfsu/CVE-2026-36392 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| FairSketch Rise CRM | <= 3.9.6 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2026 | New CVE Received | [email protected] |
Volerion