Impact
CordysCRM allows an authenticated user with MODULE_SETTING:UPDATE to supply a crafted sort.name parameter that is interpolated into a dynamic SQL ORDER BY clause. This results in a time‑based blind SQL injection that can confirm query execution, reveal database metadata, read sensitive values, and introduce delays that degrade service availability. The vulnerability is limited to authenticated API calls and does not rely on external network access.
Affected Systems
The affected product is CordysCRM, released by 1Panel-dev. Any installation using a version prior to 1.7.0 is vulnerable. The flaw is present in the POST /account-pool/page endpoint and applies when an authenticated caller has the MODULE_SETTING:UPDATE permission.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the authenticated application endpoint; an adversary must obtain credentials with update permissions to exploit the injection, which can then lead to data disclosure or service degradation.
OpenCVE Enrichment