CVE-2025-10344: HTML injection in Perfex CRM
HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameters 'name' and 'clientid' at the endpoint '/projects/project/x'.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10344?
CVE-2025-10344 is classified as a high severity vulnerability due to the potential for stored HTML injection attacks.
How do I fix CVE-2025-10344?
To fix CVE-2025-10344, ensure proper input validation and sanitization for the parameters 'name' and 'clientid' in the affected endpoint.
What systems are affected by CVE-2025-10344?
CVE-2025-10344 affects Perfex CRM version 3.2.1.
What are the potential impacts of CVE-2025-10344?
The potential impacts of CVE-2025-10344 include unauthorized execution of malicious HTML or JavaScript by users accessing compromised content.
Is CVE-2025-10344 a zero-day vulnerability?
CVE-2025-10344 is not a zero-day vulnerability as it has been publicly disclosed.