CVE-2018-18417: XSS
Published Oct 19, 2018
·Updated
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.
Affected Software
1 affected component
Creativeitem Ekushey Project Manager=3.1
Event History
Oct 19, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18417?
The severity of CVE-2018-18417 is medium, with a severity value of 5.4.
2
How does CVE-2018-18417 affect Ekushey Project Manager CRM?
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.
3
What software versions are affected by CVE-2018-18417?
CVE-2018-18417 affects version 3.1 of Creativeitem Ekushey Project Manager CRM.
4
Are there any fixes available for CVE-2018-18417?
It is recommended to update to a patched version of Ekushey Project Manager CRM to fix CVE-2018-18417.
5
What is the CWE category of CVE-2018-18417?
CVE-2018-18417 falls under CWE category 79 (Cross-Site Scripting).