VYPR

Ekushey Project Manager

by Creativeitem

CVEs (2)

  • CVE-2018-18417MedOct 19, 2018
    risk 0.38cvss 5.4epss 0.02

    In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.

  • CVE-2023-3754LowJul 19, 2023
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross…