Description
A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::applySortQuery of the file application/services/AbstractKanban.php of the component Admin Kanban Endpoint. This manipulation of the argument this causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Problem types
Product status
3.4.1
Timeline
| 2026-05-04: | Advisory disclosed |
| 2026-05-04: | VulDB entry created |
| 2026-05-05: | VulDB entry last update |
Credits
Jobyer Ahmed (Bytium LLC)
suffer (VulDB User)
suffer (VulDB User)
References
vuldb.com/vuln/360980 (VDB-360980 | CodeCanyon Perfex CRM Admin Kanban Endpoint AbstractKanban.php applySortQuery sql injection)
vuldb.com/vuln/360980/cti (VDB-360980 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/807743 (Submit #807743 | CodeCanyon Perfex CRM 3.4.1 SQL Injection)
bytium.com/insights/blind-sql-injection-in-perfex-crm-3-4-1