CVE-2018-18417 EXPLOIT
5.4
MEDIUM · CVSS 3.0 · EPSS 1.6% (pctl 76)
Patch early
A public exploit exists.
Description
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.
Scoring
| CVSS | 5.4 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 1.64% — more likely to be exploited than 76% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-10-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| creativeitem | ekushey project manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ekushey Project Manager CRM 3.1 - Cross-Site Scripting | 2018-10-25 |
References
→ the Explorer · watch your stack · NVD