Search Results (8 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108692 2 1panel-dev, Fit2cloud 2 Cordyscrm, Cordys Crm 2026-10-11 6.5 Medium
1Panel-dev CordysCRM from 1.9.0 before 1.9.2 contains a missing authorization vulnerability in eight ModuleFieldController /field/source data-source endpoints lacking permission checks. Authenticated users denied module permission can page through organization-wide leads, contacts, quotations, contracts, payment plans, payment records, orders and invoices owned by other users.
CVE-2026-108701 2 1panel-dev, Fit2cloud 2 Cordyscrm, Cordys Crm 2026-10-11 4.3 Medium
1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability in the ContractController sortModule handler for POST /contract/sort, which lacks any permission annotation. Authenticated users without contract update permission can supply a dragNodeId, stage and field values to modify any contract, including contracts in other organizations.
CVE-2026-108704 2 1panel-dev, Fit2cloud 2 Cordyscrm, Cordys Crm 2026-10-11 4.3 Medium
CordysCRM through 1.9.3 contains an authorization bypass vulnerability that allows low-privileged authenticated users to skip permission checks by setting the owner field to their own user id. Attackers can send requests to the follow/record/add endpoints to add follow-up records and overwrite follow_time and follower on any known customer, clue or opportunity.
CVE-2026-108705 2 1panel-dev, Fit2cloud 2 Cordyscrm, Cordys Crm 2026-10-11 4.3 Medium
CordysCRM through 1.9.3 contains a missing authorization vulnerability in the POST /custom-form/data/import endpoint that allows authenticated users to import data into any custom form by customFormId. Low-privileged attackers can upload Excel files with importType ADD or UPDATE to create records in, or overwrite existing records of, custom forms they cannot manage.
CVE-2026-108700 2 1panel-dev, Fit2cloud 2 Cordyscrm, Cordys Crm 2026-10-11 6.5 Medium
1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability that allows authenticated users to list business titles by calling POST /field/source/business-title without permission checks. Users lacking CONTRACT_BUSINESS_TITLE_READ can retrieve organization invoicing entities, exposing tax identification numbers, bank account numbers, opening banks, registration addresses, and phone numbers.
CVE-2026-108702 2 1panel-dev, Fit2cloud 2 Cordyscrm, Cordys Crm 2026-10-11 4.3 Medium
1Panel-dev CordysCRM through 1.9.3 lacks a PROCESS_SETTING permission check on POST /approval-flow/webhook/test, allowing any authenticated user to trigger server-side requests to attacker-supplied URLs. Attackers can redirect GET requests from a controlled host to bypass SSRFValidator and probe internal addresses through success or failure results.
CVE-2026-108703 2 1panel-dev, Fit2cloud 2 Cordyscrm, Cordys Crm 2026-10-11 5.4 Medium
CordysCRM through 1.9.3 contains a missing authorization vulnerability in POST /approval-resource/push that allows authenticated users to submit any resource for approval without ownership checks. Low-privileged attackers can supply arbitrary resourceId values for contracts, invoices, quotations or orders to alter their approval status and read approval details.
CVE-2025-70981 2 Cordys, Fit2cloud 2 Cordyscrm, Cordys Crm 2026-02-18 9.8 Critical
CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.