Impact
Ekushey Project Manager CRM 5.0 stores the system name configured by an administrator and displays it on the public login page without encoding. The value appears in a meta description, the title element, and as markup within an h4 header. Because the h4 element is parsed as HTML, any inserted script or HTML runs in the browser of anyone who loads the login form. The stored input requires an authenticated administrator to change, but once set, the malicious payload executes for all unauthenticated visitors until the setting is altered.
Affected Systems
Creativeitem’s Ekushey Project Manager CRM 5.0. Any installation that allows administrators to enter unfiltered markup in the system name field is potentially vulnerable; the vulnerability description does not narrow the version range beyond 5.0.
Risk and Exploitability
The CVSS score of 4.8 indicates medium severity. The EPSS score is not available and the issue is not listed in CISA KEV, so public exploitation is uncertain. The attack vector involves an authenticated administrator altering the system name; the payload resides in the public login page and is executed in the victim’s browser for all unauthenticated users. The vulnerability does not require network access beyond the web application, and the scope is limited to the website’s current origin; exploitation is possible without further privileges.
OpenCVE Enrichment