CordysCRM 是一个支持私有化部署的开源 AI 驱动客户关系管理系统(CRM)。在版本 1.7.4 之前, 中的 接口以及 中的 接口仅使用基础的池读取权限检查,而未绑定 的 参数,因此无法强制执行按记录级别的数据范围控制。 这使得任何拥有普通 或 权限的已认证用户,可以通过提供其他记录的 ID,利用缺乏作用域限制的主键获取接口,访问属于其他用户、部门或组织的线索(Leads)或客户账户(Accounts)。 泄露的数据包括联系人姓名、电话号码、负责人及所属部门归属信息,以及自定义字段值。该问题已在 1.7.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 1Panel-dev | CordysCRM | < 1.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63647 | 9.3 CRITICAL | CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` |
| CVE-2026-63646 | 6.9 MEDIUM | CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users |
| CVE-2026-76900 | 6.8 MEDIUM | CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runt |
| CVE-2026-76899 | 5.7 MEDIUM | CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page` |
| CVE-2026-52745 | 5.3 MEDIUM | CordysCRM: Customer Public Pool Sorting Field SQL Injection |
| CVE-2026-76902 | 5.0 MEDIUM | CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/ |
No comments yet