CVE 5.1 MEDIUM

Stored XSS in Creativeitem Ekushey CRM_CVE-2025-40989

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.

Basic Information

ID CVE-2025-40989
Source INCIBE
Published Oct 2, 2025 at 10:40

Affected Product

Vendor Creativeitem
Product Ekushey CRM
Version 5.0
Affected Versions Creativeitem Ekushey CRM 5.0

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.