CVE-2018-18417
PoC ×2—CVSS 3.0
5.4 medium
EPSS
2%p75
Published
()
Modified
Description
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.
- Vendors
- creativeitem
- Products
- ekushey project manager
- Weakness
- CWE-79
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.