Stored Cross Site Scripting in Ekushey CRM by Creativeitem
CVE-2025-40990

5.1MEDIUM

Key Information:

Vendor
CVE Published:
2 October 2025

What is CVE-2025-40990?

A Stored Cross Site Scripting vulnerability exists in Ekushey CRM v5.0, permitting unauthorized manipulation of the application due to insufficient input validation. The flaw resides in the processing of the 'title' and 'description' parameters through the '/ekushey/index.php/client/project_bug/create/xxx' endpoint. An attacker could exploit this vulnerability by sending crafted queries to an authenticated user, leading to the potential theft of session cookies and compromising user accounts. Organizations are advised to implement immediate measures to restrict vulnerable input fields and enhance overall security.

Affected Version(s)

Ekushey CRM 5.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gonzalo Aguilar GarcĂ­a (6h4ack)
.
CVE-2025-40990 : Stored Cross Site Scripting in Ekushey CRM by Creativeitem