Impact
Ekushey Project Manager CRM through version 5.0 contains a stored cross‑site scripting flaw that lets an authenticated client user insert malicious HTML or JavaScript into the Reply Ticket field. When a Staff or Administrator subsequently opens the Support Ticket detail page, the browser executes the payload. The flaw is a violation of XSS best practices and is classified as CWE‑79.
Affected Systems
Creativeitem’s Ekushey Project Manager CRM version 5.0 and earlier are affected. The vulnerability resides in the ticket reply functionality and is reachable only from within the application after user authentication.
Risk and Exploitability
CVSSv3.1 assigns a 5.1 severity, indicating a medium risk. EPSS score of 0.00165 indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. An attacker needs valid credentials to inject the payload, so the initial foothold requires compromise or theft of user accounts. Once the malicious script runs in a privileged user’s browser, the attacker could hijack sessions, steal data, or perform actions under the victim’s authority. Given the lack of a known exploit and the authentication requirement, the likelihood of widespread exploitation is moderate but not negligible.
OpenCVE Enrichment