ZeroHour

CVE-2018-18417

PoC ×2
CVSS 3.0
5.4 medium
EPSS
2%p75
Published
()
Modified
Description

In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.

Vendors
creativeitem
Products
ekushey project manager
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.