A HTML injection vulnerability exists in Perfex CRM v3.3...
High severity
Unreviewed
Published
Oct 10, 2025
to the GitHub Advisory Database
•
Updated Oct 10, 2025
Description
Published by the National Vulnerability Database
Oct 10, 2025
Published to the GitHub Advisory Database
Oct 10, 2025
Last updated
Oct 10, 2025
A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.
References