![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-3754 – Creativeitem Ekushey Project Manager CRM xxxxxxxx[random-msg-hash] cross site scripting
https://notcve.org/view.php?id=CVE-2023-3754
19 Jul 2023 — A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross site scripting. It is possible to launch the attack remotely. VDB-234426 is the identifier assigned to this vulnerability. • https://vuldb.com/?ctiid.234426 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-18417 – Ekushey Project Manager CRM 3.1 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-18417
17 Oct 2018 — In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI. En la versión 3.1 de Ekushey Project Manager CRM, se ha descubierto Cross-Site Scripting (XSS) persistente en las secciones input y upload, tal y como queda demostrado con el parámetro name en el URI index.php/admin/client/create. Ekushey Project Manager CRM version 3.1 suffers from a persistent cross site scriptin... • https://packetstorm.news/files/id/149842 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •