Junglewise Threat Intelligence

CVE-2026-66030: Creativeitem Ekushey Project Manager CRM stored XSS in Ticket Title

CVE-2026-66030 · Severity: medium · CVSS 5.4 · Published 2026-07-27

Technologies: Creativeitem Ekushey Project Manager CRM. Vendors: Creativeitem.

Executive brief

Ekushey Project Manager CRM is a customer relationship management platform used to manage projects and client support tickets. A security flaw allows users with client-level access to embed malicious scripts into support ticket titles. When a staff member or administrator views these tickets, the script executes in their browser, potentially allowing the attacker to perform unauthorized actions or steal session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Ekushey Project Manager CRM through version 5.0 due to improper neutralization of input in the 'Ticket Title' field on the 'Create New Ticket' page. An authenticated attacker with client-level privileges can submit a ticket containing a malicious JavaScript payload. This payload is stored in the database and executed in the context of Staff or Administrator users when they view the 'Client Support' or 'All Support Tickets' pages, where the title is rendered without proper sanitization. This can lead to session hijacking or unauthorized administrative actions. No patch has been officially confirmed in the provided advisory.

Affected products

  • Creativeitem Ekushey Project Manager CRM 0 through 5.0

Timeline

  • 2026-07-25: disclosed: Initial researcher disclosure
  • 2026-07-27: advisory: NVD publication date

References

Related threats