Back to CVE List

CVE-2026-66028

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.7 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H

Vulnerability Description

Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized account access.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-303
Source
NVD
Vendor
Creativeitem
Product
Ekushey Project Manager CRM

External References

Discussion (0)

Add Comment

No comments yet. Be the first!