Stored Cross Site Scripting in Ekushey CRM by Creativeitem
CVE-2025-40989
5.1MEDIUM
What is CVE-2025-40989?
A stored Cross Site Scripting vulnerability exists in Ekushey CRM version 5.0, developed by Creativeitem. This flaw arises from inadequate validation of user inputs, specifically affecting the 'message' parameter transmitted via POST requests to the '/ekushey/index.php/client/project_message/add/xxx' endpoint. An attacker could exploit this vulnerability by crafting a malicious query directed at an authenticated user, potentially enabling the theft of sensitive cookie session information.
Affected Version(s)
Ekushey CRM 5.0