peter bassill · operator
$ cve CVE-2018-18417 JSON

CVE-2018-18417 EXPLOIT

5.4
MEDIUM · CVSS 3.0 · EPSS 1.6% (pctl 76)

Patch early

A public exploit exists.

Description

In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.

Scoring

CVSS5.4 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS1.64% — more likely to be exploited than 76% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2018-10-19
Last modified2026-06-17

Affected (1)

VendorProduct
creativeitemekushey project manager

Public exploits

SourceTitleDate
exploit-dbEkushey Project Manager CRM 3.1 - Cross-Site Scripting2018-10-25

References

→ the Explorer  ·  watch your stack  ·  NVD