Vulnerability Description
A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://codecanyon.net/item/perfex-powerful-open-source-crm/14013737
- https://github.com/ajansha/CVE-2025-55903
FAQ
What is CVE-2025-55903?
CVE-2025-55903 is a vulnerability with a CVSS score of 8.3 (HIGH). A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be i...
How severe is CVE-2025-55903?
CVE-2025-55903 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55903?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.