CVE-2024-56908 Details
Description
In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directories of their choice, potentially leading to remote code execution or server compromise.
A remote code execution vulnerability exists in Perfex CRM versions prior to 3.2.1. An authenticated attacker can exploit this issue by sending a crafted HTTP POST request to the upload_sales_file endpoint. The attack involves manipulating the rel_id parameter to bypass input validation, allowing the upload of arbitrary files to user-specified directories. This exploitation could lead to remote code execution or a complete server compromise.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 13, 2025CISA-ADP
Assessed Feb 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/JuyLang/7406077e3e5e6b2ff35c80f1853e298f | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1287 | Improper Validation of Specified Type of Input | CISA-ADP |
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Perfex CRM | < 3.2.1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2025 | CVE Modified | CISA-ADP |
| Feb 13, 2025 | New CVE Received | [email protected] |
Volerion