CVE-2026-66031: Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Support Ticket detail page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66031?
The severity of CVE-2026-66031 is medium with a score of 5.4.
What type of vulnerability is CVE-2026-66031?
CVE-2026-66031 is a stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2026-66031?
To fix CVE-2026-66031, ensure input validation and sanitization of user inputs in the Reply Ticket field.
Who is affected by CVE-2026-66031?
Authenticated client users of Ekushey Project Manager CRM through version 5.0 are affected by CVE-2026-66031.
What can attackers do with CVE-2026-66031?
With CVE-2026-66031, attackers can inject and execute arbitrary HTML and JavaScript in the application.