CVE-2026-7782 PUBLISHED

CodeCanyon Perfex CRM Tenant Clients.php project authorization

Assigner: VulDB
Reserved: 04.05.2026 Published: 04.05.2026 Updated: 04.05.2026

A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Clients.php of the component Tenant Handler. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor CodeCanyon
Product Perfex CRM
Versions
  • Version 3.4.0 is affected
  • Version 3.4.1 is affected

Credits

  • suffer (VulDB User) reporter

References

Problem Types

  • Authorization Bypass CWE
  • Improper Authorization CWE