Fiche vulnérabilité
CVE-2025-40991 : faille moyenne creativeitem ekushey project manager crm (CVSS 5.4)
Description
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to "description" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.
En bref
- Sévérité
- Moyenne (CVSS 5.4)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 2 oct. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- creativeitem ekushey project manager crm