1 results (0.006 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 2

In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI. En la versión 3.1 de Ekushey Project Manager CRM, se ha descubierto Cross-Site Scripting (XSS) persistente en las secciones input y upload, tal y como queda demostrado con el parámetro name en el URI index.php/admin/client/create. Ekushey Project Manager CRM version 3.1 suffers from a persistent cross site scripting vulnerability. • https://www.exploit-db.com/exploits/45681 http://packetstormsecurity.com/files/149842/Ekushey-Project-Manager-CRM-3.1-Cross-Site-Scripting.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •