๐Ÿ” CVE Alert

CVE-2026-76899

MEDIUM 5.7

CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`

CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with MODULE_SETTING_UPDATE to place an arbitrary database function in SortRequest.name because CustomerPoolController.page omits Spring request validation, SortRequest.getName relies on an incomplete blacklist, and the CommonMapper.xml sort fragment inserts ${sortName} into an ORDER BY clause. Functions such as extractvalue and updatexml bypass the blacklist and can expose database values through an error oracle when the query returns at least one row. This issue is fixed in version 1.7.4.

CWE CWE-89 CWE-1284
Vendor 1panel-dev
Product cordyscrm
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for 1panel-dev cordyscrm

Be the first to know when new medium vulnerabilities affecting 1panel-dev cordyscrm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low

Affected Versions

1Panel-dev / CordysCRM
< 1.7.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-x6p7-vhgp-6r3q github.com: https://github.com/1Panel-dev/CordysCRM/pull/2975 github.com: https://github.com/1Panel-dev/CordysCRM/commit/3e6a7003ac5c94bc1166c6065e64420be2f188a8 github.com: https://github.com/1Panel-dev/CordysCRM/commit/b217166af2935c827c8d73bf55c563dd328692f5 github.com: https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.4