Aller au contenu

Fiche vulnérabilité

CVE-2025-40991 : faille moyenne creativeitem ekushey project manager crm (CVSS 5.4)

Description

Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to "description" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
2 oct. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • creativeitem ekushey project manager crm

Références

Rechercher une autre vulnérabilité dans la base CVE