๐Ÿ” CVE Alert

CVE-2026-52745

MEDIUM 5.3

CordysCRM: Customer Public Pool Sorting Field SQL Injection

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller with MODULE_SETTING:UPDATE to place a crafted sort.name value into a dynamic SQL ORDER BY expression without strict server-side validation of the sorting field. The resulting time-based blind SQL injection can confirm database expression execution, infer database metadata and sensitive values, and introduce database delays that degrade service. This issue is fixed in version 1.7.0.

CWE CWE-89
Vendor 1panel-dev
Product cordyscrm
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for 1panel-dev cordyscrm

Be the first to know when new medium vulnerabilities affecting 1panel-dev cordyscrm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low

Affected Versions

1Panel-dev / CordysCRM
< 1.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-xrcr-hj37-q83j github.com: https://github.com/1Panel-dev/CordysCRM/pull/2418 github.com: https://github.com/1Panel-dev/CordysCRM/commit/b5b9272c016550d80a789fd8ffbf3d5a4c4bab52 github.com: https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.0