CVE-2025-10341: HTML injection in Perfex CRM
Published Sep 29, 2025
·Updated
HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameter 'company' at the endpoint '/clients/client/x.
Affected Software
2 affected components
Perfex CRM
Perfexcrm Perfex Crm>=3.2.1<3.4.0
Event History
Sep 29, 2025
CVE Published
via MITRE·08:36 AM
Data Sourced
via MITRE·08:36 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-10341?
CVE-2025-10341 is classified as a high severity HTML injection vulnerability.
2
How do I fix CVE-2025-10341?
To fix CVE-2025-10341, ensure proper validation and sanitization of user inputs before processing them in the Perfex CRM application.
3
What software is affected by CVE-2025-10341?
CVE-2025-10341 affects Perfex CRM version 3.2.1.
4
What type of vulnerability is CVE-2025-10341?
CVE-2025-10341 is a stored HTML injection vulnerability.
5
How can CVE-2025-10341 impact users?
CVE-2025-10341 can allow attackers to inject malicious HTML content, potentially compromising user data and altering the application behavior.