PT-2026-65089 · Unknown · Ekushey Project Manager Crm
CVE-2026-66028
·
Published
2026-07-27
·
Updated
2026-07-28
CVSS v3.1
6.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ekushey Project Manager CRM versions prior to 5.1
Description
A missing uniqueness constraint allows authenticated administrators to create duplicate client accounts using identical email and password credentials. The lack of enforcement on the email field enables the creation of conflicting account states where multiple accounts share the same email address but have different passwords, leading to unpredictable authentication behavior and unauthorized account access.
Recommendations
Update Ekushey Project Manager CRM to a version newer than 5.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ekushey Project Manager Crm