Impact
CordysCRM versions up to 1.9.3 have a missing authorization flaw in the POST /approval-resource/push endpoint. An authenticated user can submit any resource ID for approval regardless of ownership, allowing low‑privileged attackers to alter the approval status of contracts, invoices, quotations or orders and read approval details. This issue maps to a credentials or privileges escalation weakness.
Affected Systems
CordysCRM from 1Panel-dev, up to and including version 1.9.3. The vulnerability exists in the web application layer of this product.
Risk and Exploitability
The CVSS v3 score of 5.3 indicates a moderate impact. The EPSS score is currently not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be carried out by any authenticated user, so it is a remotely exploitable authenticated privilege escalation. Successful exploitation permits an attacker to modify or read approval data without proper authorization.
OpenCVE Enrichment