HTML Injection Vulnerability in Perfex CRM by Perfex
CVE-2025-10346
5.3MEDIUM
What is CVE-2025-10346?
Perfex CRM v3.2.1 contains a vulnerability that allows for stored HTML injection due to inadequate validation of user input. Exploiting this flaw involves sending a specially crafted POST request to the 'knowledge_base/article' endpoint, specifically manipulating the 'subject' parameter. This could lead to the injection of malicious scripts and unauthorized access, compromising the integrity of user data.
Affected Version(s)
Perfex CRM 3.2.1