CVE-2025-55903: High severity Perfex CRM vulnerability
A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55903?
CVE-2025-55903 has been assessed as a medium severity vulnerability due to its potential for HTML injection and user impact.
How do I fix CVE-2025-55903?
To fix CVE-2025-55903, ensure to sanitize and validate user input in the 'Bill To' address field to prevent HTML injection.
What risks does CVE-2025-55903 pose?
CVE-2025-55903 poses a risk of arbitrary HTML injection, which can lead to phishing attacks or manipulation of client-facing documents.
Which versions of Perfex CRM are affected by CVE-2025-55903?
CVE-2025-55903 specifically affects Perfex CRM version 3.3.1 and potentially earlier versions.
Can CVE-2025-55903 be exploited remotely?
Yes, CVE-2025-55903 can be exploited remotely as it involves user input in a publicly accessible web application.