PT-2026-81428 · Unknown · Ekushey Project Manager Crm

·

CVE-2026-26211

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ekushey Project Manager CRM (affected versions not specified)
Description The software fails to apply output encoding to the administrator-configured system name when it is written to the login page. This value is displayed in the description meta element, the title element, and an h4 element in the page header. Because the h4 element is parsed as markup, HTML injected into the system name field is rendered, allowing any associated event handlers to execute. Since the login page is accessible without authentication, the stored script executes in the browser of all visitors, including unauthenticated users, within the origin of the login form and adjacent to credential fields.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26211

Affected Products

Ekushey Project Manager Crm