CordysCRM 是一个支持私有部署的开源 AI 驱动客户关系管理系统。在 1.7.2 版本之前, 接口在调用 时未进行身份验证,原因是 将 路径标记为匿名访问,且该控制器方法未添加任何权限注解。因此,未认证的攻击者可以获取 CRM 各模块的字段名称、数据类型、必填标志、默认值、选项、校验规则以及数据绑定来源等信息,从而重构应用的数据模型,并针对其他输入实施更具针对性的攻击。该漏洞已在 1.7.2 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 1Panel-dev | CordysCRM | < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63647 | 9.3 CRITICAL | CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` |
| CVE-2026-76900 | 6.8 MEDIUM | CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runt |
| CVE-2026-76901 | 5.8 MEDIUM | CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoint |
| CVE-2026-76899 | 5.7 MEDIUM | CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page` |
| CVE-2026-52745 | 5.3 MEDIUM | CordysCRM: Customer Public Pool Sorting Field SQL Injection |
| CVE-2026-76902 | 5.0 MEDIUM | CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/ |
No comments yet