CVE-2024-44851 — Stored XSS in Perfex CRM File Sharing module
Stored Cross-Site Scripting in the File Sharing module of Perfex CRM — disclosed and assigned CVE-2024-44851.
Summary
A stored cross-site scripting (XSS) vulnerability was identified in the File Sharing module of Perfex CRM, an open-source customer-relationship management platform.
Identifiers
- CVE: CVE-2024-44851
- Class: Stored Cross-Site Scripting (XSS)
- Component: Perfex CRM — File Sharing module
- Reporter: Ashfaqul Haq
References
For the canonical record and any update on affected versions, see the public CVE-2024-44851 entry in the NVD / MITRE CVE database.
This post is a short disclosure announcement. A longer technical writeup with the proof-of-concept payload may be published once the vendor’s remediation timeline allows.