A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Oct 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-116 | |
Metrics |
cvssV3_1
|
Fri, 10 Oct 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-10T19:56:00.613Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-55903

Updated: 2025-10-10T19:55:03.930Z

Status : Received
Published: 2025-10-10T20:15:37.433
Modified: 2025-10-10T20:15:37.433
Link: CVE-2025-55903

No data.

No data.