CVE-2018-18417

MEDIUM

Creativeitem Ekushey Project Manager - XSS

Title source: rule
STIX 2.1

Description

In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.

Exploits (1)

exploitdb WORKING POC
by Ismail Tasdelen · textwebappsphp
https://www.exploit-db.com/exploits/45681

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45681/

Scores

CVSS v3 5.4
EPSS 0.0019
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
creativeitem/ekushey_project_manager 3.1
Published Oct 19, 2018
Tracked Since Feb 18, 2026