SQL Injection Vulnerability in CordysCRM by 1Panel
CVE-2026-52745
5.3MEDIUM
What is CVE-2026-52745?
CordysCRM, an open-source AI-powered customer relationship management system, is susceptible to a time-based blind SQL injection vulnerability. An authenticated user with MODULE_SETTING:UPDATE can manipulate the sort.name parameter in the POST /account-pool/page endpoint, bypassing essential server-side validation. This exploitation leads to potential database expression execution confirmation, exposure of database metadata and sensitive information, and could exacerbate service delays. Users are encouraged to upgrade to version 1.7.0 to mitigate this issue.
Affected Version(s)
CordysCRM < 1.7.0
