First published: Mon Mar 31 2025(Updated: )
A vulnerability has been found in CodeCanyon Perfex CRM up to 3.2.1 and classified as problematic. This vulnerability affects unknown code of the file /contract of the component Contracts. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Perfex CRM | <=3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2974 is classified as problematic and poses a risk of cross-site scripting.
To fix CVE-2025-2974, upgrade CodeCanyon Perfex CRM to a version beyond 3.2.1.
CVE-2025-2974 affects the Contracts component of CodeCanyon Perfex CRM.
CVE-2025-2974 allows manipulation of content leading to cross-site scripting vulnerabilities.
CVE-2025-2974 affects all versions of CodeCanyon Perfex CRM up to and including 3.2.1.