# Exploit Title: Create-Project Manager 1.07 Multi XSS /HTML injection Vunlerabilities # Google Dork:N/A # Date: 2020-05-06 # Exploit Author: @ThelastVvV # Vendor Homepage: https://codecanyon.net/item/create-project-manager-with-authenticator/20483329?s_rank=3 # Version: 1.6 # Tested on: 5.4.0-kali4-amd64 --------------------------------------------------------- About : Create! freelancer manager is a complete project management solution for developers, freelancers and software companies, it offers powerful tools for project development, tracking each developer work time for each project, generating invoices for online payment, complete social network with chat and news feed for developers, and powerful financial section for income and expenses.. Summary: Multi Persistent Cross-site Scripting and HTML injection in Create 1.07 - Freelancer Project Manager PoC : 1- Go to any of following: A-Online chat B-Social feed C-Message (title-tag) B-Add new client (all-tags) 2- In the text field type your payload :