Arbitrary Database Function Injection in CordysCRM by 1Panel
CVE-2026-76899

5.7MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-76899?

CordysCRM, an open-source AI-enhanced customer relationship management system, has a flaw allowing authenticated users with MODULE_SETTING_UPDATE permission to execute arbitrary database functions. This stemmed from inadequate request validation in the 'CustomerPoolController.page' method, leading to an insufficient blacklist in 'SortRequest.getName'. The vulnerability can be exploited through the POST /account-pool/page endpoint, where functions like 'extractvalue' and 'updatexml' can execute, potentially revealing sensitive database information through an error oracle if the query returns results. This vulnerability has been addressed in version 1.7.4.

Affected Version(s)

CordysCRM < 1.7.4

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.