In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directories of their choice, potentially leading to remote code execution or server compromise.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-1287 CWE-444 |
|
Metrics |
cvssV3_1
|
Thu, 13 Feb 2025 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directories of their choice, potentially leading to remote code execution or server compromise. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-02-13T00:00:00.000Z
Updated: 2025-03-17T18:48:25.965Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-56908

Updated: 2025-02-19T16:19:02.401Z

Status : Awaiting Analysis
Published: 2025-02-13T23:15:10.773
Modified: 2025-03-17T19:15:24.050
Link: CVE-2024-56908

No data.