Perfex CRM
cpe:2.3:a:perfexcrm:perfex_crm:*:*:*:*:*:*:*
- 3.2.1
A stored HTML injection vulnerability has been identified in Perfex CRM version 3.2.1. This vulnerability arises from inadequate validation of user input, allowing malicious HTML to be injected and stored by sending a POST request with the 'name' and 'clientid' parameters to the '/projects/project/x' endpoint.
Exploitation of this vulnerability allows for stored HTML injection, where injected HTML is executed in the context of the user.
Users are advised to update to the latest version of Perfex CRM, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.