
Proof of concept for CVE-2025-55903, a stored HTML injection in PerfexCRM allowing authenticated users to inject malicious HTML into invoices and client communications, leading to phishing and malware distribution.
⚠️ Security Advisory
A critical Stored HTML Injection vulnerability affecting invoices, billing, and automated communications
A Stored HTML Injection vulnerability has been discovered in PerfexCRM that allows authenticated users to inject malicious HTML into invoice descriptions, billing addresses, and client notes. This injected content persists in the database and is automatically rendered in client-facing emails and PDF attachments, enabling large-scale phishing attacks, business email compromise, and potential malware delivery.
| Attribute | Value |
|---|---|
| CVE ID | CVE-2025-55903 |
| Type | Stored HTML Injection |
| Attack Vector | Network/Remote |
| Authentication | Required (Low Privilege) |
| User Interaction | None |
| Severity | HIGH |
| CVSS v3.1 | 8.1 - High |
| Discoverer | Ajansha Shankar |
PerfexCRM fails to properly sanitize and encode HTML content in multiple user-editable fields. When authenticated users inject HTML payloads into invoice line item descriptions, billing address fields, or client notes, the content is stored in the database without adequate filtering. Subsequently, this malicious HTML is automatically rendered in client-facing emails and PDF attachments without proper escaping, leading to widespread distribution of phishing content and malware.
| Factor | Impact | Explanation |
|---|---|---|
| Confidentiality | 🔴 HIGH | Client credentials and sensitive data can be harvested via phishing |
| Integrity | 🔴 HIGH | Malicious content can modify perception of communications |
| Availability | 🟡 LOW | Limited direct impact on system availability |
An attacker with low-privilege access creates an invoice with malicious HTML:
<a href="https://attacker.com/fake-login">Click here to verify payment</a>
The invoice is sent to 50+ clients via automated email. All clients receive what appears to be a legitimate invoice directing them to a phishing site. The attacker harvests credentials from multiple victims simultaneously.
Navigate to: PerfexCRM Admin Dashboard → Invoices → Create New Invoice
<a href="https://attacker.com">Click here to view invoice</a>
<a href="https://evil.com" target="_blank">
<img src="https://media1.giphy.com/media/v1.Y2lkPTc5MGI3NjExbzg4OXRuZHd4MXF0bWNqa3BvN2pzbWdqMzRxZHc5bHJpbXpucHNtaSZlcD12MV9pbnRlcm5hbF9naWZfYnlfaWQmY3Q9Zw/9PgvV8ale90lQwfQTZ/giphy.gif">
</a>
<h1><font color=red>Visit Our New WebSite</font></h1>
<h3><mark><a href="https://evil.com">https://www.paytm.com/</a></mark></h3>
✅ Injected HTML renders in both email and PDF without escaping ✅ Links are clickable and redirect to attacker sites ✅ Images load from attacker-controlled servers ✅ Content persists across all future client communications
Discovered by: Ajansha Shankar
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Score: 8.1 (HIGH)
Breakdown:
⭐ If this research was helpful, please consider starring this repository!
🔔 Stay updated: Watch this repository for updates on this and future security research.