CVE-2026-52745
Last modified
CVE-2026-52745 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller with MODULE_SETTING:UPDATE to place a crafted sort.name value into a dynamic SQL ORDER BY expression without strict server-side validation of the sorting field. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller with MODULE_SETTING:UPDATE to place a crafted sort.name value into a dynamic SQL ORDER BY expression without strict server-side validation of the sorting field. The resulting time-based blind SQL injection can confirm database expression execution, infer database metadata and sensitive values, and introduce database delays that degrade service. This issue is fixed in version 1.7.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| 1Panel-dev | CordysCRM | < 1.7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-52745?
How severe is CVE-2026-52745?
How do I fix CVE-2026-52745?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5274Integer overflow in Codecs in Google Chrome prior to 146.0.7…8.8
- CVE-2026-52740GoCD is a continuous deliver server. From 18.7.0 until 26.1.…5.3
- CVE-2026-52741GoCD is a continuous deliver server. From 18.3.0 until 26.1.…7.5
- CVE-2026-52742GoCD is a continuous deliver server. From 12.3.1 until 26.1.…5.1
- CVE-2026-52743GoCD is a continuous deliver server. Prior to 26.1.0, the in…4.3
- CVE-2026-52744GoCD is a continuous deliver server. From 20.2.0 until 26.1.…5.3
- CVE-2026-52746JSONata is a JSON query and transformation language. Prior t…7.5
- CVE-2026-52747ModSecurity is an open source, cross platform web applicatio…8.6
- CVE-2026-5275Heap buffer overflow in ANGLE in Google Chrome on Mac prior …8.8
- CVE-2026-52750Ghidra before 12.1 contains a command injection vulnerabilit…8.4
- CVE-2026-52751Ghidra before 12.1 contains an unsafe deserialization vulner…8.8
- CVE-2026-52752Ghidra before 12.0.2 contains a path traversal vulnerability…8.4
Are you affected by CVE-2026-52745?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
