Perfex CRM
cpe:2.3:a:perfexcrm:perfex_crm:*:*:*:*:*:*:*
- 3.2.1
A stored HTML injection vulnerability has been identified in Perfex CRM version 3.2.1. This vulnerability arises from inadequate validation of user input, allowing malicious HTML to be injected and stored by sending a POST request with specific parameters. The issue is present in the 'knowledge_base/article' endpoint, where the 'subject' parameter can be exploited.
Exploitation of this vulnerability allows for stored HTML injection, where injected HTML is saved and can be executed in the context of the user.
Users are advised to update to the latest version of Perfex CRM, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.