PT-2026-95642 · Cordyscrm · Cordyscrm
CVE-2026-52745
·
Published
2026-09-18
·
Updated
2026-09-19
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
CordysCRM versions prior to 1.7.0
Description
The POST '/account-pool/page' endpoint allows an authenticated user with
MODULE SETTING:UPDATE permissions to inject a crafted sort.name value into a dynamic SQL ORDER BY expression due to a lack of strict server-side validation. This leads to a time-based blind SQL injection, which is a technique used to infer data from a database by observing the time it takes for the server to respond to specific queries. An attacker can use this to confirm the execution of database expressions, extract sensitive values and metadata, or cause database delays that degrade service performance.Recommendations
Update to version 1.7.0.
Avoid using the
sort.name parameter in the '/account-pool/page' endpoint until the update is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cordyscrm