PT-2025-39814 · Unknown · Perfex Crm

CVE-2025-10341

·

Publicado

2025-09-29

·

Atualizado

2025-09-29

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Perfex CRM version 3.2.1
Description An HTML injection issue exists in Perfex CRM version 3.2.1. The issue is due to insufficient validation of user-supplied data. An attacker can inject HTML code by sending a POST request to the /clients/client/x endpoint with malicious content in the company parameter. This allows for stored HTML injection.
Recommendations Apply input validation and sanitization to the company parameter in the /clients/client/x endpoint.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-10341

Produtos afetados

Perfex Crm