PT-2026-95661 · Cordyscrm · Cordyscrm

CVE-2026-76899

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions CordysCRM versions 1.7.0 through 1.7.3
Description An authenticated user with MODULE SETTING UPDATE permissions can execute arbitrary database functions via the POST /account-pool/page endpoint. This occurs because the CustomerPoolController.page function lacks Spring request validation, and the SortRequest.getName function uses an incomplete blacklist. Consequently, the CommonMapper.xml sort fragment inserts the sortName variable directly into an ORDER BY clause. Attackers can use functions like extractvalue and updatexml to bypass the blacklist and retrieve database values through an error oracle, which is a technique used to extract data by analyzing the error messages returned by the database.
Recommendations Update to version 1.7.4. Avoid using the sortName variable in the POST /account-pool/page endpoint until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76899
GHSA-X6P7-VHGP-6R3Q

Affected Products

Cordyscrm