Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-10343


HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameter 'expense_name' at the endpoint '/expenses/expense'.


Published

2025-09-29T09:15:34.770

Last Modified

2025-10-02T19:47:50.333

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application perfexcrm perfex_crm < 3.4.0 Yes

References