Stored Cross Site Scripting in Ekushey CRM by Creativeitem
CVE-2025-40990
5.1MEDIUM
What is CVE-2025-40990?
A Stored Cross Site Scripting vulnerability exists in Ekushey CRM v5.0, permitting unauthorized manipulation of the application due to insufficient input validation. The flaw resides in the processing of the 'title' and 'description' parameters through the '/ekushey/index.php/client/project_bug/create/xxx' endpoint. An attacker could exploit this vulnerability by sending crafted queries to an authenticated user, leading to the potential theft of session cookies and compromising user accounts. Organizations are advised to implement immediate measures to restrict vulnerable input fields and enhance overall security.
Affected Version(s)
Ekushey CRM 5.0