Impact
The flaw allows an authenticated user possessing the MODULE_SETTING_UPDATE permission to inject arbitrary database functions into the SortRequest.name field of POST /account-pool/page. The controller passes the value directly into an ORDER BY clause without proper validation, enabling functions such as extractvalue and updatexml to leak database contents through error messages. This leads to confidential data disclosure and could enable further misuse if other vulnerable endpoints are present.
Affected Systems
CordysCRM versions 1.7.0 through 1.7.4 are affected. The vulnerability exists only when the user is authenticated and has MODULE_SETTING_UPDATE rights. All earlier versions prior to 1.7.0 and 1.7.4 or later are not impacted.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity and the EPSS data is unavailable, so the risk cannot be quantified precisely, but the vulnerability is not listed in KEV. The likely attack vector is an internal or compromised account that can send authenticated POST requests. While the impact is limited to data exposure rather than a full code execution, the availability of extractvalue and updatexml functions can expose sensitive information. Proper mitigation is required even though the exploit is not trivial.
OpenCVE Enrichment