/ WEB EXPLOITATION · CVE-2024-44851 — STORED XSS IN PERFEX CRM FILE SHARING MODULE
— · — · — v 4.2 · MMXXVI

CVE-2024-44851 — Stored XSS in Perfex CRM File Sharing module

Stored Cross-Site Scripting in the File Sharing module of Perfex CRM — disclosed and assigned CVE-2024-44851.

Summary

A stored cross-site scripting (XSS) vulnerability was identified in the File Sharing module of Perfex CRM, an open-source customer-relationship management platform.

Identifiers

  • CVE: CVE-2024-44851
  • Class: Stored Cross-Site Scripting (XSS)
  • Component: Perfex CRM — File Sharing module
  • Reporter: Ashfaqul Haq

References

For the canonical record and any update on affected versions, see the public CVE-2024-44851 entry in the NVD / MITRE CVE database.

This post is a short disclosure announcement. A longer technical writeup with the proof-of-concept payload may be published once the vendor’s remediation timeline allows.