Back to search
CVE-2025-10345
Published: Sep 29, 2025
Modified: Sep 29, 2025
PUBLISHED
Description
HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameters 'name' and 'address' at the endpoint 'admin/leads/lead'.
| Vendor | Product | Versions |
|---|---|---|
Perfex CRM | Perfex CRM | affected 3.2.1 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now