Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-60375

Опубликовано: 09 окт. 2025
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password parameters in the login request, an attacker can gain unauthorized access to user accounts, including administrative accounts, without providing valid credentials.

EPSS

Процентиль: 22%
0.00074
Низкий

7.3 High

CVSS3

Дефекты

CWE-289

Связанные уязвимости

CVSS3: 7.3
github
4 месяца назад

The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password parameters in the login request, an attacker can gain unauthorized access to user accounts, including administrative accounts, without providing valid credentials.

EPSS

Процентиль: 22%
0.00074
Низкий

7.3 High

CVSS3

Дефекты

CWE-289