Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8702 | A vulnerability has been found in CodeCanyon Perfex CRM up to 3.2.1 and classified as problematic. This vulnerability affects unknown code of the file /contract of the component Contracts. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 02 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Perfexcrm
Perfexcrm perfex Crm |
|
| CPEs | cpe:2.3:a:perfexcrm:perfex_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Perfexcrm
Perfexcrm perfex Crm |
Mon, 31 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in CodeCanyon Perfex CRM up to 3.2.1 and classified as problematic. This vulnerability affects unknown code of the file /contract of the component Contracts. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | CodeCanyon Perfex CRM Contracts contract cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-03-31T16:04:34.258Z
Reserved: 2025-03-30T07:34:47.846Z
Link: CVE-2025-2974
Updated: 2025-03-31T16:04:29.570Z
Status : Analyzed
Published: 2025-03-31T04:15:17.633
Modified: 2025-10-02T15:36:16.090
Link: CVE-2025-2974
No data.
OpenCVE Enrichment
No data.
EUVD