CVE-2025-60375: High severity Perfex CRM vulnerability
The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password parameters in the login request, an attacker can gain unauthorized access to user accounts, including administrative accounts, without providing valid credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60375?
CVE-2025-60375 is considered a high severity vulnerability due to its potential for unauthorized access to user accounts.
How do I fix CVE-2025-60375?
To fix CVE-2025-60375, update Perfex CRM to version 3.3.1 or later which addresses the authentication bypass issue.
What are the potential impacts of CVE-2025-60375?
The potential impacts of CVE-2025-60375 include unauthorized access to user accounts, compromising sensitive information and administrative capabilities.
Who is affected by CVE-2025-60375?
CVE-2025-60375 affects all versions of Perfex CRM prior to 3.3.1.
What type of vulnerability is CVE-2025-60375?
CVE-2025-60375 is an authentication bypass vulnerability that allows attackers to log in without valid credentials.