{"id":"CVE-2026-52745","title":"CordysCRM is an open source AI-powered customer relationship management system that supports private deployment","summary":"CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller with MODULE_SETTING:UPDATE to place a cr…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L","cwe":["CWE-89"],"vendor":"1Panel-dev","product":"CordysCRM","affected":["CordysCRM < 1.7.0"],"published":"2026-09-18","updated":"2026-09-19","sourceUpdated":"2026-09-19T14:16:58.153","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-52745","references":[{"url":"https://github.com/1Panel-dev/CordysCRM/commit/b5b9272c016550d80a789fd8ffbf3d5a4c4bab52","label":"security-advisories@github.com"},{"url":"https://github.com/1Panel-dev/CordysCRM/pull/2418","label":"security-advisories@github.com"},{"url":"https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.0","label":"security-advisories@github.com"},{"url":"https://github.com/1Panel-dev/CordysCRM/security/advisories/GHSA-xrcr-hj37-q83j","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-19T13:38:03.983559Z"},"epss":0.00283,"epssPercentile":0.20987,"ingestedAt":"2026-09-18T20:51:25.673Z","slug":"CVE-2026-52745","body":"## Overview\n\nCordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller with MODULE_SETTING:UPDATE to place a crafted sort.name value into a dynamic SQL ORDER BY expression without strict server-side validation of the sorting field. The resulting time-based blind SQL injection can confirm database expression execution, infer database metadata and sensitive values, and introduce database delays that degrade service. This issue is fixed in version 1.7.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}