Impact
CordysCRM exposes its Server‑Sent Events API to the public. An attacker can supply any userId to the /sse/subscribe endpoint and receive that user’s workflow events, approval requests, mentions, and alerts. The API also allows unauthenticated users to send SYSTEM_HEARTBEAT messages via /sse/broadcast and to terminate other users’ channels with /sse/close. The missing authentication and improper user validation give the attacker read, write, and control capabilities over other users’ streams, resulting in confidentiality loss, UI manipulation, and potential denial of service. The weakness is a lack of authentication and authorization checks.
Affected Systems
The issue exists in the 1Panel‑dev CordysCRM distribution prior to version 1.7.2. Only that vendor and product are affected; the specific pre‑1.7.2 releases are vulnerable.
Risk and Exploitability
The CVSS score of 9.3 reflects critical severity, and the EPSS score is not available, but the vulnerability is trivially exploitable over the network because the endpoints are publicly accessible. An unauthenticated attacker can simply issue HTTP requests with a chosen userId to pull data or manipulate streams. The vulnerability is not listed in the CISA KEV catalog, yet the combination of high severity and ease of exploitation warrants immediate action. The likely attack vector is a conventional HTTP request to the public /sse/* endpoints, where the attacker supplies a userId to hijack another user’s stream.
OpenCVE Enrichment