Summary
A business logic flaw in the project management application allows a Project Manager to store arbitrary HTML markup in a project's name without proper server-side validation or sanitization.
By placing a specially crafted HTML payload in the Project Name field, the project can enter a corrupted state where the malicious value is no longer visibly displayed. However, the value remains stored and later interferes with the application's note-creation workflow.
As a result, any user who attempts to create a note on the affected project—including an Administrator—receives a server-side error and cannot create the note.
This makes the issue particularly impactful because a lower-privileged Project Manager can silently corrupt a project and cause a functionality denial that persists across users and sessions.