PT-2026-95661 · Cordyscrm · Cordyscrm
CVE-2026-76899
·
Published
2026-09-18
·
Updated
2026-09-23
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
CordysCRM versions 1.7.0 through 1.7.3
Description
An authenticated user with
MODULE SETTING UPDATE permissions can execute arbitrary database functions via the POST /account-pool/page endpoint. This occurs because the CustomerPoolController.page function lacks Spring request validation, and the SortRequest.getName function uses an incomplete blacklist. Consequently, the CommonMapper.xml sort fragment inserts the sortName variable directly into an ORDER BY clause. Attackers can use functions like extractvalue and updatexml to bypass the blacklist and retrieve database values through an error oracle, which is a technique used to extract data by analyzing the error messages returned by the database.Recommendations
Update to version 1.7.4.
Avoid using the
sortName variable in the POST /account-pool/page endpoint until the update is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cordyscrm