HTML Injection Vulnerability in Perfex CRM by Perfex CRM
CVE-2025-55903
Key Information:
- Vendor
Perfex CRM
- Status
- Vendor
- CVE Published:
- 10 October 2025
Badges
What is CVE-2025-55903?
An HTML injection vulnerability exists in Perfex CRM v3.3.1 due to insufficient sanitization of user input within the 'Bill To' address field of the estimate module. This flaw permits the injection of arbitrary HTML, which is rendered unescaped in client-facing documents, potentially compromising the integrity and security of outputted data and affecting user trust. Prompt attention and remediation are advised to mitigate exploitation risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
