Arbitrary Database Function Injection in CordysCRM by 1Panel
CVE-2026-76899
5.7MEDIUM
What is CVE-2026-76899?
CordysCRM, an open-source AI-enhanced customer relationship management system, has a flaw allowing authenticated users with MODULE_SETTING_UPDATE permission to execute arbitrary database functions. This stemmed from inadequate request validation in the 'CustomerPoolController.page' method, leading to an insufficient blacklist in 'SortRequest.getName'. The vulnerability can be exploited through the POST /account-pool/page endpoint, where functions like 'extractvalue' and 'updatexml' can execute, potentially revealing sensitive database information through an error oracle if the query returns results. This vulnerability has been addressed in version 1.7.4.
Affected Version(s)
CordysCRM < 1.7.4
