Impact
The flaw in CordysCRM’s approval‑flow webhook handling allows an attacker with PROCESS_SETTING_ADD privileges to define a custom webHookUrl that the server will request when an approval action is executed. This absence of SSRF validation lets the application contact arbitrary internal URLs, potentially exposing cloud metadata, discovering internal services, and performing unauthorized interactions with internal infrastructure. The weakness results in confidentiality leakage through outbound requests made by the server on the attacker’s behalf.
Affected Systems
This vulnerability exists in 1Panel‑dev CordysCRM version 1.7.3 and earlier. It has been mitigated in the 1.7.4 release. Systems running the affected version require an upgrade or a restrictive permission model to prevent abuse of the remediation process.
Risk and Exploitability
The CVSS score of 6.8 categorizes the issue as medium severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. However, the attacker must possess the PROCESS_SETTING_ADD permission, meaning that internal users or compromised accounts with that role could exploit the flaw. Once the attacker configures a malicious URL and triggers an approval action, the application will perform an HTTP request to that URL, providing a vector for reconnaissance or data exfiltration of internal services.
OpenCVE Enrichment