<?xml version="1.0" encoding="utf-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>NULL CATHEDRAL - Perfex-Crm</title><link>https://nullcathedral.com/tags/perfex-crm/</link><description>Where nothing is sacred.</description><language>en-us</language><copyright>NULL CATHEDRAL</copyright><pubDate>Mon, 16 Mar 2026 00:00:00 +0000</pubDate><lastBuildDate>Fri, 10 Apr 2026 18:00:00 +0000</lastBuildDate><docs>https://www.rssboard.org/rss-specification</docs><ttl>60</ttl><atom:link href="https://nullcathedral.com/tags/perfex-crm/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://nullcathedral.com/favicon.svg</url><title>NULL CATHEDRAL</title><link>https://nullcathedral.com/</link></image><item><title>Perfex CRM &lt;=3.4.0 allows unauthenticated RCE via insecure deserialization</title><link>https://nullcathedral.com/posts/2026-03-16-perfex-crm-unauthenticated-rce-insecure-deserialization/</link><description>Perfex CRM passed the autologin cookie into unserialize() without validation, giving unauthenticated attackers remote code execution.</description><category>vulnerability</category><category>perfex-crm</category><category>deserialization</category><category>rce</category><category>php</category><guid isPermaLink="true">https://nullcathedral.com/posts/2026-03-16-perfex-crm-unauthenticated-rce-insecure-deserialization/</guid><pubDate>Mon, 16 Mar 2026 00:00:00 +0000</pubDate></item></channel></rss>