PT-2025-39818 · Unknown · Perfex Crm

Published

2025-09-29

·

Updated

2025-09-29

·

CVE-2025-10345

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Perfex CRM version 3.2.1
Description An HTML injection issue exists in Perfex CRM version 3.2.1. This is due to insufficient validation of user-supplied data. The issue occurs when sending a POST request to the /admin/leads/lead endpoint with malicious HTML code in the name and address parameters. This allows for stored HTML injection.
Recommendations Apply appropriate input validation and sanitization to the name and address parameters in the /admin/leads/lead endpoint.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-10345

Affected Products

Perfex Crm