Ghostwire

CVE-2026-108701: 1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability in the ContractController sortModule...

MEDIUM CVSS 4.3 Exploit Available

Published: October 11, 2026 | Last Modified: October 11, 2026

Description

1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability in the ContractController sortModule handler for POST /contract/sort, which lacks any permission annotation. Authenticated users without contract update permission can supply a dragNodeId, stage and field values to modify any contract, including contracts in other organizations.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References