Impact
A stored cross‑site scripting flaw in Creativeitem Ekushey Project Manager CRM up to version 5.0 allows authenticated client users to inject arbitrary HTML or JavaScript into the Ticket Title field on the Create New Ticket page. When a staff or administrator later views the Client Support page where that title is rendered without sanitization, the malicious payload runs in their browser. The execution can enable arbitrary client‑side actions within the application, potentially compromising the victim’s session context.
Affected Systems
The vulnerability affects Creativeitem Ekushey Project Manager CRM version 5.0 and earlier releases. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score of < 1% suggests a very low but non‑zero probability of exploitation, and it is not listed in the CISA KEV catalog, so active exploitation activity is uncertain. Attackers need only authenticated client access to create a malicious ticket and to trigger execution when staff or administrators later view the unsanitized title, allowing them to run code in the victim’s browser session.
OpenCVE Enrichment