Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-60375 — Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access. | Kitploit
Tools/GitHubGitHub/ajansha/cve-2025-60375
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthentication
GitHubajansha/cve-2025-60375

CVE-2025-60375

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

View Repository
10 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-60375 — PerfexCRM Authentication Bypass

Advisory ID: perfexcrm-auth-bypass-2025
CVE: CVE-2025-60375
Product: PerfexCRM
Affected versions: versions prior to 3.3.1 (< 3.3.1)
Reported by: Ajansha Shankar, Ahamed Yaseen
References: OWASP Authentication Cheat Sheet — https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html


Summary

An authentication bypass exists in the admin login mechanism of PerfexCRM prior to version 3.3.1. The server's authentication workflow does not sufficiently validate the presence and contents of username/password parameters. An attacker who manipulates the login request to supply empty username and password parameters may be granted access to user accounts, including administrative accounts.


Impact

  • Unauthorized access to user accounts (including admin).
  • Potential full compromise of the application and sensitive data exposure.
  • Remote exploitation — attacker only needs the ability to send HTTP requests to the login endpoint.

Technical details & reproduction

  1. Intercept the POST request sent to the admin login endpoint (e.g., /admin/auth/login).
  • Remove or set username and password fields to empty values in the request body.
  • Forward the modified request. The server may respond with 419 Page expired on refresh but will redirect to the dashboard and provide an authenticated session without valid credentials.
  • Root cause (summary): insufficient server-side validation and improper control flow that allows session or application logic to mark the request as authenticated even with missing credentials.


    Mitigation / Remediation

    • Fix server-side authentication: reject requests missing username or password with an explicit 4xx error (e.g., 400/401).
    • Ensure session creation and privilege assignment only happen after successful credential verification.
    • Add unit and integration tests to validate behavior against empty/missing credential values.
    • Consider adding rate-limiting and monitoring for suspicious login attempts while fix is deployed.

    Suggested CVSS (example)

    • CVSS v3.1 (example): 7.8 (High) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

    Note: This is an estimated vector for triage. Provide a precise CVSS vector after coordinated disclosure.


    Contact / Credit

    • Reported by: Ajansha Shankar and Ahamed Yaseen

    Reference

    https://www.cve.org/CVERecord?id=CVE-2025-60375 https://www.tenable.com/cve/CVE-2025-60375

    Download Tool