CVE-2025-60375
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
09/10/2025
Última modificación:
14/10/2025
Descripción
*** Pendiente de traducción *** The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password parameters in the login request, an attacker can gain unauthorized access to user accounts, including administrative accounts, without providing valid credentials.
Impacto
Puntuación base 3.x
7.30
Gravedad 3.x
ALTA



