
CVE-2025-60375 — Authentication bypass / incorrect access control in PerfexCRM < 3.3.1 (admin login)
CVE-2025-60375 — Authentication bypass / incorrect access control in PerfexCRM < 3.3.1 (admin login)
Vulnerability type: Incorrect Access Control — Authentication bypass
Affected product: PerfexCRM < 3.3.1
CVE: CVE-2025-60375 (Published)
Brief description:
The authentication mechanism in PerfexCRM versions prior to 3.3.1 fails to validate username/password parameters server-side. By sending empty username and password parameters in an intercepted login request, an attacker can bypass authentication and gain access to accounts (including admin accounts).
username and password parameters in the login request payload (send empty parameters).419 Page expired then automatic redirect to the dashboard.Note: Steps above are the original discovery steps reported by Ajansha Shankar and Ahamed Yaseen.
Ahamed Yaseen , Ajansha Shankar