PT-2026-95642 · Cordyscrm · Cordyscrm

CVE-2026-52745

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions CordysCRM versions prior to 1.7.0
Description The POST '/account-pool/page' endpoint allows an authenticated user with MODULE SETTING:UPDATE permissions to inject a crafted sort.name value into a dynamic SQL ORDER BY expression due to a lack of strict server-side validation. This leads to a time-based blind SQL injection, which is a technique used to infer data from a database by observing the time it takes for the server to respond to specific queries. An attacker can use this to confirm the execution of database expressions, extract sensitive values and metadata, or cause database delays that degrade service performance.
Recommendations Update to version 1.7.0. Avoid using the sort.name parameter in the '/account-pool/page' endpoint until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52745
GHSA-XRCR-HJ37-Q83J

Affected Products

Cordyscrm