What is CVE-2026-66030?
This is a stored cross-site scripting (XSS) vulnerability affecting Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject arbitrary HTML and JavaScript via the 'Ticket Title' field on the 'Create New Ticket' page. Affected systems should be immediately updated to the latest version or apply the vendor-provided patch.
Azərbaycanca: Bu, Ekushey Project Manager CRM-in 5.0 versiyasına qədər təsir edən stored cross-site scripting (XSS) boşluğudur. Autentifikasiya olunmuş müştəri istifadəçiləri 'Create New Ticket' səhifəsindəki 'Ticket Title' sahəsinə zərərli HTML/JavaScript yükləyə bilər. Təsirə məruz qalan sistemlər dərhal ən son versiyaya yenilənməli və ya vendor tərəfindən təqdim edilən yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Ekushey
FAQ2
Does exploiting CVE-2026-66030 in Ekushey Project Manager CRM require authentication?
Yes, the vulnerability can only be exploited by authenticated client users.
What mitigation is recommended for the CVE-2026-66030 vulnerability?
Affected systems should be immediately updated to the latest version or apply the vendor-provided patch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.