Description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with MODULE_SETTING_UPDATE to place an arbitrary database function in SortRequest.name because CustomerPoolController.page omits Spring request validation, SortRequest.getName relies on an incomplete blacklist, and the CommonMapper.xml sort fragment inserts ${sortName} into an ORDER BY clause. Functions such as extractvalue and updatexml bypass the blacklist and can expose database values through an error oracle when the query returns at least one row. This issue is fixed in version 1.7.4.
Published: 2026-09-18
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection with potential data exposure
Action: Apply Patch
AI Analysis

Impact

The flaw allows an authenticated user possessing the MODULE_SETTING_UPDATE permission to inject arbitrary database functions into the SortRequest.name field of POST /account-pool/page. The controller passes the value directly into an ORDER BY clause without proper validation, enabling functions such as extractvalue and updatexml to leak database contents through error messages. This leads to confidential data disclosure and could enable further misuse if other vulnerable endpoints are present.

Affected Systems

CordysCRM versions 1.7.0 through 1.7.4 are affected. The vulnerability exists only when the user is authenticated and has MODULE_SETTING_UPDATE rights. All earlier versions prior to 1.7.0 and 1.7.4 or later are not impacted.

Risk and Exploitability

The CVSS score of 5.7 indicates moderate severity and the EPSS data is unavailable, so the risk cannot be quantified precisely, but the vulnerability is not listed in KEV. The likely attack vector is an internal or compromised account that can send authenticated POST requests. While the impact is limited to data exposure rather than a full code execution, the availability of extractvalue and updatexml functions can expose sensitive information. Proper mitigation is required even though the exploit is not trivial.

Generated by OpenCVE AI on September 19, 2026 at 11:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CordysCRM to version 1.7.4 or later, where the issue is fixed.
  • Limit the MODULE_SETTING_UPDATE permission to only trusted administrators to reduce the number of accounts that can exploit the flaw.
  • If an upgrade is not immediately possible, apply input validation to the sort name parameter or alter the database query to use parameterized statements that reject unsanitized values and block direct calls to extractvalue and updatexml.

Generated by OpenCVE AI on September 19, 2026 at 11:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared 1panel-dev
1panel-dev cordyscrm
Vendors & Products 1panel-dev
1panel-dev cordyscrm

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with MODULE_SETTING_UPDATE to place an arbitrary database function in SortRequest.name because CustomerPoolController.page omits Spring request validation, SortRequest.getName relies on an incomplete blacklist, and the CommonMapper.xml sort fragment inserts ${sortName} into an ORDER BY clause. Functions such as extractvalue and updatexml bypass the blacklist and can expose database values through an error oracle when the query returns at least one row. This issue is fixed in version 1.7.4.
Title CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`
Weaknesses CWE-1284
CWE-89
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L'}


Subscriptions

1panel-dev Cordyscrm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T21:05:27.034Z

Reserved: 2026-08-19T22:43:14.890Z

Link: CVE-2026-76899

cve-icon Vulnrichment

Updated: 2026-09-24T21:03:59.050Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:21.600

Modified: 2026-09-24T21:18:36.350

Link: CVE-2026-76899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:15:06Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')