A vulnerability was found in Creativeitem Ekushey Project Manager CRM up to 5.0. It has been declared as problematic. Affected is an unknown function of the component Edit Profile. Executing a manipulation of the argument client Name can lead to cross site scripting.
This vulnerability is handled as CVE-2026-66029. The attack can be executed remotely. There is not any exploit available.