CVE-2026-26211: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Creativeitem Ekushey Project Manager CRM
Description
CVE-2026-26211 is a stored cross-site scripting (XSS) vulnerability in Creativeitem Ekushey Project Manager CRM. The system name configured by an administrator is output on the login page without proper encoding, allowing HTML and event handlers to execute in the browser of any visitor to the login page. This vulnerability requires administrator privileges to store the malicious payload but affects unauthenticated visitors who load the login page. The vulnerability persists until the system name setting is changed.
CVSS v4.0
Score 4.8medium
Affected software
Creativeitem
Ekushey Project Manager CRM
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because the administrator-configured system name is written to the login page in three locations without output encoding: the content attribute of the description meta element, the title element, and an h4 element in the page header. The h4 element is parsed as markup, so injected HTML and event handlers execute in the context of the login page. Since the login page is publicly accessible without authentication, any visitor loading it will execute the stored script within the origin of the site. Exploitation requires an administrator session to store the malicious system name, but the impact affects all visitors until the setting is changed.
Potential Impact
An attacker with administrator privileges can inject malicious scripts that execute in the browsers of all visitors to the login page, including unauthenticated users. This can lead to theft of credentials entered on the login page or other malicious actions performed within the context of the vulnerable site. The vulnerability persists until the system name is changed, making it a persistent stored XSS risk.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should avoid entering untrusted input into the system name field. If possible, restrict administrator access to trusted personnel only. Monitor for unusual activity related to the system name setting and consider temporarily disabling or restricting access to the login page if exploitation is suspected.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-02-11T20:08:07.942Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8dd2e5acd9273b4981f095
Added to database: 08/25/2026, 17:37:41 UTC
Last enriched: 09/10/2026, 18:07:37 UTC
Last updated: 10/10/2026, 06:48:15 UTC
Views: 40
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.