Junglewise Threat Intelligence

CVE-2026-66029: Creativeitem Ekushey Project Manager CRM stored XSS in client Name field

CVE-2026-66029 · Severity: medium · CVSS 5.4 · Published 2026-07-27

Technologies: Creativeitem Ekushey Project Manager CRM. Vendors: Creativeitem.

Executive brief

Ekushey Project Manager CRM, a tool used for managing business projects and client relationships, contains a security flaw in how it handles user profile information. An authenticated client user can save a malicious script in their profile name field, which then automatically runs in the browsers of staff members or administrators when they view the client list. This could allow a low-privileged user to hijack administrative sessions, steal sensitive session data, or perform unauthorized actions on behalf of company staff.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Ekushey Project Manager CRM through version 5.0 due to insufficient input sanitization and output encoding of the client Name field. An authenticated attacker with 'Client' privileges can inject malicious JavaScript payloads via the 'Edit Profile' page. This script is stored in the database and subsequently executed in the security context of higher-privileged users (Staff or Administrators) when they visit the 'Manage Clients' or 'Manage Client Projects' pages. This can lead to session hijacking, unauthorized data access, or administrative account takeover. As of the advisory date, no official patch has been confirmed.

Affected products

  • Creativeitem Ekushey Project Manager CRM through 5.0

Timeline

  • 2026-07-25: disclosed: Researcher disclosure date
  • 2026-07-27: advisory: NVD and VulnCheck publication date

References

Related threats