Perfex CRM HTML Injection Vulnerability

Vulnerability

A stored HTML injection vulnerability has been identified in Perfex CRM version 3.2.1. This vulnerability arises from inadequate validation of user input, allowing malicious HTML to be injected and stored by sending a POST request with the 'name' and 'address' parameters to the 'admin/leads/lead' endpoint.

Impact

Exploitation of this vulnerability allows for stored HTML injection, where injected HTML is executed in the context of the user.

Remediation

Users are advised to update to the latest version of Perfex CRM, where this vulnerability has been fixed.

Added: Sep 29, 2025, 9:17 AM
Updated: Sep 29, 2025, 9:17 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.7
exploitability
4.6
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.