CVE-2026-66028
Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email
CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting account states where multiple accounts share the same email address with different passwords, resulting in unpredictable authentication behavior and unauthorized account access.
| CWE | CWE-303 |
| Vendor | creativeitem |
| Product | ekushey project manager crm |
| Published | Jul 27, 2026 |
| Last Updated | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for creativeitem ekushey project manager crm
Be the first to know when new medium vulnerabilities affecting creativeitem ekushey project manager crm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High
Affected Versions
Creativeitem / Ekushey Project Manager CRM
0 โค 5.0
References
Credits
Aaron Amran Bin Amiruddin