Impact
An unauthenticated attacker can retrieve any file uploaded by users in other organizations by guessing or observing numerical identifiers. The service performs a straight primary‑key lookup without enforcing ownership or permission checks, allowing cross‑organization data exposure. This flaw causes a confidential information leak rather than direct code execution or denial of service.
Affected Systems
CordysCRM, an open source AI‑powered customer relationship management system developed by 1Panel‑dev. The vulnerability is present in all releases prior to 1.7.4 and is addressed in version 1.7.4. The affected endpoints are /attachment/preview/{id} and /pic/preview/{id} which are mistakenly marked as anonymous in the Shiro security filter configuration.
Risk and Exploitability
The CVSS score of 5 indicates moderate severity. Because the exploitation requires only unauthenticated HTTP requests and the attacker needs to guess or observe the ID, the attack is feasible once valid identifiers are discovered. The EPSS score is not available, but the exposure of cross‑organization data could have business and privacy implications. The vulnerability is not listed in CISA's KEV catalog, suggesting no publicly known active attacks yet, but the risk of data leakage remains significant if the flaw persists.
OpenCVE Enrichment