CVE-2025-10346: HTML injection in Perfex CRM
Published Sep 29, 2025
·Updated
HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameters 'subject' at the endpoint 'knoewledgebase/article'.
Affected Software
2 affected components
Perfex CRM
Perfexcrm Perfex Crm>=3.2.1<3.4.0
Event History
Sep 29, 2025
CVE Published
via MITRE·08:43 AM
Data Sourced
via MITRE·08:43 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Apr 15, 57724
Event
via NVD·06:16 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-10346?
CVE-2025-10346 is classified as a high-severity HTML injection vulnerability.
2
How do I fix CVE-2025-10346?
To fix CVE-2025-10346, ensure proper validation and sanitization of user inputs in the 'subject' parameter.
3
What is the impact of CVE-2025-10346?
The impact of CVE-2025-10346 includes the potential for attackers to inject malicious HTML into the system, compromising user sessions.
4
What software versions are affected by CVE-2025-10346?
CVE-2025-10346 affects Perfex CRM version 3.2.1.
5
How can I prevent similar vulnerabilities like CVE-2025-10346 in the future?
To prevent similar vulnerabilities, implement strict input validation and employ security measures like Content Security Policy (CSP).