HTML Injection Vulnerability in Perfex CRM by Perfex
CVE-2025-10343
5.3MEDIUM
What is CVE-2025-10343?
A security flaw in Perfex CRM v3.2.1 allows attackers to perform stored HTML injection through improper validation of user inputs. This vulnerability occurs when a POST request is sent to the '/expenses/expense' endpoint with the parameter 'expense_name'. Exploiting this can lead to unauthorized manipulation of web content, potentially compromising sensitive data and overall system integrity.
Affected Version(s)
Perfex CRM 3.2.1