Home

Description

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.

PUBLISHED Reserved 2025-08-16 | Published 2025-10-10 | Updated 2025-10-10 | Assigner mitre

References

codecanyon.net/item/perfex-powerful-open-source-crm/14013737

github.com/ajansha/CVE-2025-55903

cve.org (CVE-2025-55903)

nvd.nist.gov (CVE-2025-55903)

Download JSON