Stored Cross Site Scripting in Ekushey CRM by Creativeitem
CVE-2025-40990
What is CVE-2025-40990?
A Stored Cross Site Scripting vulnerability exists in Ekushey CRM v5.0, permitting unauthorized manipulation of the application due to insufficient input validation. The flaw resides in the processing of the 'title' and 'description' parameters through the '/ekushey/index.php/client/project_bug/create/xxx' endpoint. An attacker could exploit this vulnerability by sending crafted queries to an authenticated user, leading to the potential theft of session cookies and compromising user accounts. Organizations are advised to implement immediate measures to restrict vulnerable input fields and enhance overall security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Ekushey CRM 5.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
