Description
1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability that allows authenticated users to list business titles by calling POST /field/source/business-title without permission checks. Users lacking CONTRACT_BUSINESS_TITLE_READ can retrieve organization invoicing entities, exposing tax identification numbers, bank account numbers, opening banks, registration addresses, and phone numbers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 11 Oct 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel-dev
1panel-dev cordyscrm |
|
| Vendors & Products |
1panel-dev
1panel-dev cordyscrm |
Sun, 11 Oct 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability that allows authenticated users to list business titles by calling POST /field/source/business-title without permission checks. Users lacking CONTRACT_BUSINESS_TITLE_READ can retrieve organization invoicing entities, exposing tax identification numbers, bank account numbers, opening banks, registration addresses, and phone numbers. | |
| Title | 1Panel-dev CordysCRM before 1.9.2 Missing Authorization via /field/source/business-title | |
| First Time appeared |
Fit2cloud
Fit2cloud cordys Crm |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:fit2cloud:cordys_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fit2cloud
Fit2cloud cordys Crm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T01:12:27.065Z
Reserved: 2026-10-10T23:08:36.706Z
Link: CVE-2026-108700
No data.
Status : Deferred
Published: 2026-10-11T02:16:38.277
Modified: 2026-10-11T02:16:38.397
Link: CVE-2026-108700
No data.
OpenCVE Enrichment
Updated: 2026-10-11T03:15:08Z
Weaknesses
-
CWE-862
Missing Authorization