CVE-2025-10345: HTML injection in Perfex CRM
HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameters 'name' and 'address' at the endpoint 'admin/leads/lead'.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10345?
CVE-2025-10345 is classified as a high severity vulnerability due to its potential for stored HTML injection.
How do I fix CVE-2025-10345?
To fix CVE-2025-10345, ensure proper validation and sanitization of user inputs in the parameters 'name' and 'address' at the 'admin/leads/lead' endpoint.
What versions of Perfex CRM are affected by CVE-2025-10345?
CVE-2025-10345 affects Perfex CRM version 3.2.1 and potentially earlier versions that lack the necessary security measures.
What type of vulnerability is CVE-2025-10345?
CVE-2025-10345 is an HTML injection vulnerability that allows attackers to inject malicious HTML code due to inadequate input validation.
Who should be concerned about CVE-2025-10345?
Administrators and users of Perfex CRM v3.2.1 should be concerned about CVE-2025-10345 due to its implications for data security and integrity.