PT-2025-41488 · Unknown · Perfex Crm

Ahamed Yaseen

+1

·

Publicado

2025-10-09

·

Atualizado

2025-10-09

·

CVE-2025-60375

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Perfex CRM versions prior to 3.3.1
Description The authentication process in Perfex CRM has a flaw where server-side validation is inadequate. This allows attackers to bypass normal login procedures by submitting empty values for the username and password parameters in a login request. Successful exploitation grants unauthorized access to user accounts, potentially including administrative accounts.
Recommendations Update Perfex CRM to version 3.3.1 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-60375

Produtos afetados

Perfex Crm