Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/CordysCRM

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-108705 is a missing authorization vulnerability in CordysCRM versions up to 1.9.3. It affects the POST /custom-form/data/import endpoint, allowing authenticated low-privileged users to import data into any custom form by specifying the customFormId. Attackers can upload Excel files with importType ADD or UPDATE to create or overwrite records in custom forms they should not have access to.

Join the discussion

CordysCRM versions up to 1.9.3 contain an authorization bypass vulnerability that allows low-privileged authenticated users to bypass permission checks by manipulating the owner field. This enables attackers to add follow-up records and overwrite certain fields on customer, clue, or opportunity records.

Join the discussion

CordysCRM versions up to 1.9.3 have a missing authorization vulnerability in the POST /approval-resource/push endpoint. This flaw allows authenticated users with low privileges to submit any resource for approval without verifying ownership. Attackers can manipulate approval statuses and read approval details of contracts, invoices, quotations, or orders by supplying arbitrary resourceId values.

Join the discussion

CVE-2026-108702 is a medium severity vulnerability in 1Panel-dev CordysCRM versions up to 1.9.3. It involves a missing authorization check on the POST /approval-flow/webhook/test endpoint, allowing any authenticated user to trigger server-side requests to attacker-controlled URLs. This can be exploited to bypass SSRF protections and probe internal network addresses.

Join the discussion

CVE-2026-108701 is a missing authorization vulnerability in 1Panel-dev CordysCRM versions before 1.9.2. The flaw exists in the ContractController sortModule handler for the POST /contract/sort endpoint, which lacks permission checks. Authenticated users without contract update permissions can modify any contract, including those belonging to other organizations.

Join the discussion

CVE-2026-108700 is a missing authorization vulnerability in 1Panel-dev CordysCRM versions before 1.9.2. Authenticated users without the CONTRACT_BUSINESS_TITLE_READ permission can call a specific API endpoint to list business titles and retrieve sensitive organization invoicing data, including tax IDs, bank account details, and contact information.

Join the discussion

CVE-2026-108692 is a missing authorization vulnerability in 1Panel-dev CordysCRM versions 1.9.0 up to but not including 1.9.2. It affects eight ModuleFieldController endpoints related to data-source fields, which lack proper permission checks. Authenticated users without module permissions can access organization-wide data including leads, contacts, quotations, contracts, payment plans, payment records, orders, and invoices owned by other users.

Join the discussion

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with MODULE_SETTING_UPDATE to place an arbitrary database function in SortRequest.name because CustomerPoolController.page omits Spring request validation, SortRequest.getName relies on an incomplete blacklist, and the CommonMapper.xml sort fragment inserts ${sortName} into an ORDER BY clause. Functions such as extractvalue and updatexml bypass the blacklist and can expose database values through an error oracle when the query returns at least one row. This issue is fixed in version 1.7.4.

Join the discussion

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configures /attachment/preview/{id} and /pic/preview/{id} as anonymous, and both routes call AttachmentService.getResource, which performs a bare primary-key lookup without ownership, organization, or permission checks. An unauthenticated caller who guesses or observes an id generated by IDGenerator.nextStr can download files uploaded by users in other organizations because the stored organization id is used only to locate the file rather than authorize the caller. This issue is fixed in version 1.7.4.

Join the discussion

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration and passes it through ApprovalFlowService.updateApprovalPostField to HttpClientUtils without the SSRF validation used by the optional testConnect path. A user with PROCESS_SETTING_ADD can configure an internal URL through POST /approval-flow/add and cause the server to request it when POST /approval-action/approve executes the approval action, enabling cloud metadata access, internal network reconnaissance, and interaction with reachable internal services. This issue is fixed in version 1.7.4.

Join the discussion

Showing 1 to 10 of 19 results

Filters:Package: pkg:github/CordysCRM
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses