CVE-2025-2974 Overview
CVE-2025-2974 is a stored cross-site scripting (XSS) vulnerability in CodeCanyon Perfex CRM versions up to and including 3.2.1. The flaw resides in the Contracts component, specifically the /contract endpoint. An authenticated attacker can manipulate the content parameter to inject persistent JavaScript payloads. When another user views the affected contract, the injected script executes in their browser session. The vulnerability is tracked under CWE-79 and has been publicly disclosed, making exploitation instructions available to threat actors.
Critical Impact
Attackers with low-privilege access can persist malicious JavaScript in contract records, enabling session hijacking, credential theft, and unauthorized actions against higher-privileged CRM users.
Affected Products
- CodeCanyon Perfex CRM versions up to and including 3.2.1
- Deployments exposing the Contracts module (/contract) to authenticated users
- Any installation where the content field accepts unsanitized HTML input
Discovery Timeline
- 2025-03-31 - CVE-2025-2974 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-2974
Vulnerability Analysis
CVE-2025-2974 is a stored cross-site scripting vulnerability affecting the Contracts module of Perfex CRM. The vulnerability arises because the application accepts user-controlled input through the content argument of the /contract endpoint without applying sufficient output encoding or input sanitization. Injected script payloads are persisted in the backend database and rendered to any subsequent user who views the affected contract.
The attack requires network access and low-level authentication. User interaction is required, as a victim must view the contract that contains the injected payload. Because the payload executes in the context of the victim's authenticated session, it can be leveraged to perform actions on behalf of privileged users, including administrators.
Root Cause
The root cause is improper neutralization of input during web page generation [CWE-79]. The content parameter within the Contracts module is stored and later rendered without HTML encoding or script filtering. This allows attacker-controlled markup and JavaScript to be executed by the victim's browser when the contract is displayed.
Attack Vector
An authenticated attacker submits a crafted contract containing a JavaScript payload embedded in the content field. The malicious content is stored server-side. When another user opens or previews the contract, the browser parses the injected script and executes it within the CRM origin. See the Bytium Stored XSS Advisory and VulDB entry #302026 for technical details on the injection point.
Detection Methods for CVE-2025-2974
Indicators of Compromise
- Contract records in the Perfex CRM database containing HTML tags such as <script>, <img onerror=>, or <svg onload=> inside the content field
- Outbound HTTP requests from user browsers to attacker-controlled domains shortly after loading a /contract page
- Unexpected session cookie transmissions or new administrator sessions originating from unusual IP addresses
- Anomalous POST requests to /contract from low-privileged accounts containing encoded script payloads
Detection Strategies
- Inspect web server access logs for POST requests to /contract containing URL-encoded angle brackets, javascript: schemes, or event handler attributes
- Query the CRM database for contract records whose content column contains suspicious HTML or JavaScript keywords
- Deploy a web application firewall rule that flags HTML tags submitted to the Contracts module endpoint
Monitoring Recommendations
- Enable verbose auditing on the Contracts module and forward logs to a centralized SIEM for correlation
- Alert on administrator account activity that immediately follows a contract view event by a low-privileged user
- Monitor Content Security Policy (CSP) violation reports for inline script executions on CRM pages
How to Mitigate CVE-2025-2974
Immediate Actions Required
- Restrict access to the Contracts module to trusted users until a vendor patch is applied
- Audit existing contract records for stored payloads and remove any suspicious HTML or scripts from the content field
- Rotate session tokens and administrator credentials if compromise is suspected
- Deploy a web application firewall rule blocking script tags and event handler attributes submitted to /contract
Patch Information
At the time of publication, no vendor advisory or fixed release has been recorded in the enriched CVE data. Administrators should monitor the CodeCanyon Perfex CRM product page and the Bytium advisory for updates. Upgrade to a version later than 3.2.1 as soon as the vendor releases a security fix.
Workarounds
- Enforce a strict Content Security Policy that disallows inline scripts and restricts script sources to trusted origins
- Configure a reverse proxy or WAF to strip or reject HTML markup submitted to the content parameter
- Limit the Contracts module role permissions so only trusted staff can create or edit contracts
- Educate CRM users to avoid opening contracts from unfamiliar submitters until the vulnerability is patched
# Example ModSecurity rule to block script tags in the content parameter
SecRule REQUEST_URI "@beginsWith /contract" \
"phase:2,chain,deny,status:403,id:1002974,\
msg:'CVE-2025-2974 Perfex CRM Contracts XSS attempt'"
SecRule ARGS:content "@rx (?i)(<script|onerror=|onload=|javascript:)" \
"t:none,t:urlDecodeUni,t:htmlEntityDecode"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
