CVE-2025-10342: HTML injection in Perfex CRM
HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameter 'name' at the endpoint '/subscriptions/create'.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10342?
CVE-2025-10342 has a high severity rating due to the potential for stored HTML injection and its impact on user data.
How do I fix CVE-2025-10342?
To fix CVE-2025-10342, ensure proper validation and sanitization of user input in the 'name' parameter at the '/subscriptions/create' endpoint.
What are the potential impacts of CVE-2025-10342?
The potential impacts of CVE-2025-10342 include the injection of malicious HTML content that could compromise user sessions or data integrity.
Which version of Perfex CRM is affected by CVE-2025-10342?
Perfex CRM version 3.2.1 is specifically affected by CVE-2025-10342 due to its lack of input validation.
Who is the vendor associated with CVE-2025-10342?
The vendor associated with CVE-2025-10342 is Perfex, the creator of Perfex CRM.