PT-2025-39815 · Unknown · Perfex Crm

Published

2025-09-29

·

Updated

2025-09-29

·

CVE-2025-10342

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Perfex CRM version 3.2.1
Description A stored HTML injection exists due to insufficient validation of user-supplied data. The issue is triggered by sending a POST request to the /subscriptions/create API endpoint with malicious content in the name parameter. This allows for the injection of arbitrary HTML code.
Recommendations Apply input validation and sanitization to the name parameter in the /subscriptions/create API endpoint.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-10342

Affected Products

Perfex Crm