CVE-2026-66028
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
6.7 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Vulnerability Description
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized account access.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-303
Source
NVD
Vendor
Creativeitem
Product
Ekushey Project Manager CRM
Discussion (0)
Add Comment
No comments yet. Be the first!