CordysCRM 是一个支持私有化部署的开源 AI 驱动的客户关系管理系统。在 1.7.2 版本之前, 中的 、 和 端点对匿名访问开放。这是因为 方法将 SSE 路径配置为公共路径,允许未经身份验证的请求访问;同时,这些端点信任调用者传入的 参数,而非从已认证的用户身份(principal)中推导用户标识。 由于缺乏基于会话的身份验证机制,未认证的调用者可以: 通过 读取其他用户的工作流事件、审批请求、提及消息和警报; 通过 向其他用户的流中注入 消息; 通过 终止其他用户的 SSE 连接。 该漏洞已在 1.7
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 1Panel-dev | CordysCRM | < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63646 | 6.9 MEDIUM | CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users |
| CVE-2026-76900 | 6.8 MEDIUM | CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runt |
| CVE-2026-76901 | 5.8 MEDIUM | CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoint |
| CVE-2026-76899 | 5.7 MEDIUM | CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page` |
| CVE-2026-52745 | 5.3 MEDIUM | CordysCRM: Customer Public Pool Sorting Field SQL Injection |
| CVE-2026-76902 | 5.0 MEDIUM | CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/ |
No comments yet