CVE-2025-40991: Stored XSS in Creativeitem Ekushey CRM
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/projectfile/upload/xxxx", affecting to "description" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40991?
CVE-2025-40991 has a moderate severity rating due to its potential to enable stored cross site scripting attacks.
How do I fix CVE-2025-40991?
To fix CVE-2025-40991, implement proper input validation and sanitization for the 'description' parameter used in file uploads.
What systems are affected by CVE-2025-40991?
CVE-2025-40991 affects Ekushey CRM version 5.0 by Creativeitem.
What could happen if CVE-2025-40991 is exploited?
If exploited, CVE-2025-40991 could allow an attacker to execute malicious scripts in the context of the victim's browser.
Is CVE-2025-40991 present in earlier versions of Ekushey CRM?
There is no information indicating that CVE-2025-40991 is present in versions of Ekushey CRM prior to v5.0.