In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directories of their choice, potentially leading to remote code execution or server compromise.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 17 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1287 CWE-444 |
|
| Metrics |
cvssV3_1
|
Thu, 13 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directories of their choice, potentially leading to remote code execution or server compromise. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-02-13T00:00:00.000Z
Updated: 2025-03-17T18:48:25.965Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-56908
Updated: 2025-02-19T16:19:02.401Z
Status : Awaiting Analysis
Published: 2025-02-13T23:15:10.773
Modified: 2025-03-17T19:15:24.050
Link: CVE-2024-56908
No data.