Description
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized.
Published: 2026-07-27
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored cross‑site scripting flaw in Creativeitem Ekushey Project Manager CRM up to version 5.0 allows authenticated client users to inject arbitrary HTML or JavaScript into the Ticket Title field on the Create New Ticket page. When a staff or administrator later views the Client Support page where that title is rendered without sanitization, the malicious payload runs in their browser. The execution can enable arbitrary client‑side actions within the application, potentially compromising the victim’s session context.

Affected Systems

The vulnerability affects Creativeitem Ekushey Project Manager CRM version 5.0 and earlier releases. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score of < 1% suggests a very low but non‑zero probability of exploitation, and it is not listed in the CISA KEV catalog, so active exploitation activity is uncertain. Attackers need only authenticated client access to create a malicious ticket and to trigger execution when staff or administrators later view the unsanitized title, allowing them to run code in the victim’s browser session.

Generated by OpenCVE AI on August 3, 2026 at 16:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of Ekushey Project Manager CRM or apply any vendor‑supplied patch that removes the stored XSS vulnerability.
  • Ensure that any user‑supplied content, particularly the Ticket Title field, is properly escaped or sanitized on the server side before rendering.
  • Implement a stringent Content Security Policy that restricts inline script execution and limits script sources to trusted domains.

Generated by OpenCVE AI on August 3, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Description Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized. Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized.
First Time appeared Creativeitem
Creativeitem ekushey Project Manager Crm
CPEs cpe:2.3:a:creativeitem:ekushey_project_manager_crm:*:*:*:*:*:*:*:*
Vendors & Products Creativeitem
Creativeitem ekushey Project Manager Crm

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized.
Title Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Creativeitem Ekushey Project Manager Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T15:20:26.176Z

Reserved: 2026-07-23T20:45:17.816Z

Link: CVE-2026-66030

cve-icon Vulnrichment

Updated: 2026-07-28T15:07:56.378Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T18:17:00.390

Modified: 2026-07-28T20:37:39.353

Link: CVE-2026-66030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')