Description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller with MODULE_SETTING:UPDATE to place a crafted sort.name value into a dynamic SQL ORDER BY expression without strict server-side validation of the sorting field. The resulting time-based blind SQL injection can confirm database expression execution, infer database metadata and sensitive values, and introduce database delays that degrade service. This issue is fixed in version 1.7.0.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Moderate Data Exposure and Denial of Service
Action: Upgrade
AI Analysis

Impact

CordysCRM allows an authenticated user with MODULE_SETTING:UPDATE to supply a crafted sort.name parameter that is interpolated into a dynamic SQL ORDER BY clause. This results in a time‑based blind SQL injection that can confirm query execution, reveal database metadata, read sensitive values, and introduce delays that degrade service availability. The vulnerability is limited to authenticated API calls and does not rely on external network access.

Affected Systems

The affected product is CordysCRM, released by 1Panel-dev. Any installation using a version prior to 1.7.0 is vulnerable. The flaw is present in the POST /account-pool/page endpoint and applies when an authenticated caller has the MODULE_SETTING:UPDATE permission.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the authenticated application endpoint; an adversary must obtain credentials with update permissions to exploit the injection, which can then lead to data disclosure or service degradation.

Generated by OpenCVE AI on September 19, 2026 at 10:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official CordysCRM version 1.7.0 or later to eliminate the vulnerability
  • Revoke or remove MODULE_SETTING:UPDATE privileges from users that do not require update access
  • Implement input validation on the sort.name parameter to reject any characters beyond a whitelist of allowed column names

Generated by OpenCVE AI on September 19, 2026 at 10:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared 1panel-dev
1panel-dev cordyscrm
Vendors & Products 1panel-dev
1panel-dev cordyscrm

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller with MODULE_SETTING:UPDATE to place a crafted sort.name value into a dynamic SQL ORDER BY expression without strict server-side validation of the sorting field. The resulting time-based blind SQL injection can confirm database expression execution, infer database metadata and sensitive values, and introduce database delays that degrade service. This issue is fixed in version 1.7.0.
Title CordysCRM: Customer Public Pool Sorting Field SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L'}


Subscriptions

1panel-dev Cordyscrm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-19T14:01:29.368Z

Reserved: 2026-06-08T14:00:43.573Z

Link: CVE-2026-52745

cve-icon Vulnrichment

Updated: 2026-09-19T14:00:57.358Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:16.337

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-52745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:45:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')