In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directories of their choice, potentially leading to remote code execution or server compromise.
                
            References
                    Configurations
                    No configuration.
History
                    17 Mar 2025, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| CWE | CWE-1287 CWE-444 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.8 | 
13 Feb 2025, 23:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-02-13 23:15
Updated : 2025-03-17 19:15
NVD link : CVE-2024-56908
Mitre link : CVE-2024-56908
CVE.ORG link : CVE-2024-56908
JSON object : View
Products Affected
                No product.
