What is CVE-2026-66031?
A stored XSS vulnerability in Ekushey Project Manager CRM up to version 5.0 allows authenticated client users to inject arbitrary HTML and JavaScript via the Reply Ticket field. Attackers can craft and store malicious scripts that execute in other users' browsers. It is recommended to update the platform to the latest version immediately and review user inputs.
Azərbaycanca: Ekushey Project Manager CRM-in 5.0 versiyasına qədər olan sistemlərində aşkar edilmiş saxlanılan XSS zəifliyidir. Doğrulanmış müştəri istifadəçiləri Reply Ticket sahəsinə zərərli HTML/JavaScript kodu daxil edərək, digər istifadəçilərin brauzerində icra oluna biləcək skriptlər yerləşdirə bilərlər. Dərhal platformanı ən son versiyaya yeniləmək və daxilolmaları yoxlamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Ekushey
FAQ2
Does exploiting CVE-2026-66031 in Ekushey Project Manager CRM require authentication?
Yes, the vulnerability can be exploited by authenticated client users. An attacker must be logged into the system to inject malicious code via the Reply Ticket field.
Which versions of Ekushey Project Manager CRM are vulnerable to CVE-2026-66031?
Ekushey Project Manager CRM versions up to 5.0 are vulnerable to this stored XSS vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.