In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directories of their choice, potentially leading to remote code execution or server compromise.
References
Configurations
No configuration.
History
17 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-1287 CWE-444 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
13 Feb 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-13 23:15
Updated : 2025-03-17 19:15
NVD link : CVE-2024-56908
Mitre link : CVE-2024-56908
CVE.ORG link : CVE-2024-56908
JSON object : View
Products Affected
No product.