Impact
The vulnerability exists in CordysCRM version 1.9.3. The POST /custom-form/data/import endpoint lacks authorization checks, allowing any authenticated user to specify a customFormId and upload an Excel file with importType ADD or UPDATE. This results in the creation of new records or overwriting of existing ones in custom forms that the user is not permitted to manage. The impact is primarily a compromise of data integrity, enabling unauthorized manipulation of stored information.
Affected Systems
CordysCRM version 1.9.3, distributed by 1Panel-dev (identified as fit2cloud:cordys_crm). All releases through 1.9.3 are affected, allowing any authenticated user to import data into any custom form regardless of their privileges.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as medium severity, and the absence of an EPSS score precludes any quantitative estimate of exploitation probability. The attack requires authenticated access, so an adversary who can log into the system (even with low privileges) can exploit the missing authorization check to add or overwrite records in any custom form. Although the impact is limited to data integrity, the ease of exploitation and lack of restrictions on the endpoint make this a non‑negligible risk for environments where sensitive data is stored in custom forms.
OpenCVE Enrichment