Impact
CordysCRM exposes the GET /mcp/form/config/{formKey} endpoint without requiring authentication. The ShiroFilter configuration treats all /mcp/ paths as anonymous, and the controller lacks permission annotations, enabling unauthenticated users to retrieve detailed field metadata for CRM modules. The leaked information includes field names, data types, required flags, default values, options, validation rules, and binding sources, which can be used to reconstruct the application’s data model and facilitate more targeted attacks on other inputs.
Affected Systems
The vulnerability affects versions of CordysCRM released by 1Panel-dev prior to 1.7.2. The issue is addressed in version 1.7.2 and later releases.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability falls into the moderate severity range, and its EPSS score is currently unavailable. The endpoint is publicly accessible over HTTP, making discovery straightforward for remote attackers. Although the vulnerability does not grant direct code execution, the disclosed model information can aid attackers in planning subsequent data ingestion or injection attacks, increasing overall risk. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment