SQL Injection Vulnerability in CordysCRM by 1Panel
CVE-2026-52745

5.3MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-52745?

CordysCRM, an open-source AI-powered customer relationship management system, is susceptible to a time-based blind SQL injection vulnerability. An authenticated user with MODULE_SETTING:UPDATE can manipulate the sort.name parameter in the POST /account-pool/page endpoint, bypassing essential server-side validation. This exploitation leads to potential database expression execution confirmation, exposure of database metadata and sensitive information, and could exacerbate service delays. Users are encouraged to upgrade to version 1.7.0 to mitigate this issue.

Affected Version(s)

CordysCRM < 1.7.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.