A vulnerability marked as problematic has been reported in Creativeitem Ekushey Project Manager CRM up to 5.0. This issue affects some unknown processing. Performing a manipulation of the argument Reply Ticket results in cross site scripting.

This vulnerability is identified as CVE-2026-66031. The attack can be initiated remotely. There is not any exploit available.