PT-2026-95659 · Cordyscrm · Cordyscrm
CVE-2026-63646
·
Published
2026-09-18
·
Updated
2026-09-18
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CordysCRM versions prior to 1.7.2
Description
An authentication bypass exists in the
getMcpField() function of the McpController because the ShiroFilter.addPublicPathFilters method marks the /mcp/** path as anonymous and the controller lacks a permission annotation. An unauthenticated user can access the 'GET /mcp/form/config/{formKey}' endpoint to retrieve sensitive information about CRM modules, including field names, types, required flags, default values, options, validation rules, and binding sources. This exposure allows an attacker to reconstruct the application data model to facilitate more targeted attacks against other inputs.Recommendations
Update to version 1.7.2.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cordyscrm