CVE-2026-76899
5.7 MEDIUMpublic exploit availablePublished 2026-09-18 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with MODULE_SETTING_UPDATE to place an arbitrary database function in SortRequest.name because CustomerPoolController.page omits Spring request validation, SortRequest.getName relies on an incomplete blacklist, and the CommonMapper.xml sort fragment inserts ${sortName} into an ORDER BY clause. Functions such as extractvalue and updatexml bypass the blacklist and can expose database values through an error oracle when the query returns at least one row. This issue is fixed in version 1.7.4.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
Weaknesses
CWE-89, CWE-1284
Public exploit & PoC references
- https://github.com/1Panel-dev/CordysCRM/commit/3e6a7003ac5c94bc1166c6065e64420be2f188a8
- https://github.com/1Panel-dev/CordysCRM/commit/b217166af2935c827c8d73bf55c563dd328692f5
- https://github.com/1Panel-dev/CordysCRM/pull/2975
- https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.4
- https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-x6p7-vhgp-6r3q
All references
- https://github.com/1Panel-dev/CordysCRM/commit/3e6a7003ac5c94bc1166c6065e64420be2f188a8
- https://github.com/1Panel-dev/CordysCRM/commit/b217166af2935c827c8d73bf55c563dd328692f5
- https://github.com/1Panel-dev/CordysCRM/pull/2975
- https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.4
- https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-x6p7-vhgp-6r3q
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2015-20122
- HIGHCVE-2019-25776PoC
- HIGHCVE-2021-48008
- HIGHCVE-2022-4997
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- MEDIUMCVE-2025-36178
- CRITICALCVE-2025-63564
Related by shared AI tags and CWE weakness class. Browse the full archive.