CVE-2025-3219: CodeCanyon Perfex CRM Project Discussions Module 2 cross site scripting
A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown function of the file /perfex/clients/project/2 of the component Project Discussions Module. The manipulation of the argument description leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3219?
CVE-2025-3219 is classified as a problematic vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2025-3219?
To fix CVE-2025-3219, sanitize user inputs in the Project Discussions Module to prevent script injection.
Which components are affected by CVE-2025-3219?
CVE-2025-3219 affects the Project Discussions Module in CodeCanyon Perfex CRM version 3.2.1.
What type of attack is associated with CVE-2025-3219?
CVE-2025-3219 is associated with cross-site scripting (XSS) attacks that can manipulate the argument description.
Who is the vendor of the affected software for CVE-2025-3219?
The vendor of the affected software for CVE-2025-3219 is CodeCanyon.