In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.Referenceshttps://www.exploit-db.com/exploits/43590/http://packetstormsecurity.com/files/145903/PerfexCRM-1.9.7-Arbitrary-File-Upload.html