1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability that allows authenticated users to list business titles by calling POST /field/source/business-title without permission checks. Users lacking CONTRACT_BUSINESS_TITLE_READ can retrieve organization invoicing entities, exposing tax identification numbers, bank account numbers, opening banks, registration addresses, and phone numbers.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability that allows authenticated users to list business titles by calling POST /field/source/business-title without permission checks. Users lacking CONTRACT_BUSINESS_TITLE_READ can retrieve organization invoicing entities, exposing tax identification numbers, bank account numbers, opening banks, registration addresses, and phone numbers. | |
| Title | 1Panel-dev CordysCRM before 1.9.2 Missing Authorization via /field/source/business-title | |
| First Time appeared |
Fit2cloud
Fit2cloud cordys Crm |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:fit2cloud:cordys_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fit2cloud
Fit2cloud cordys Crm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T01:12:27.065Z
Reserved: 2026-10-10T23:08:36.706Z
Link: CVE-2026-108700
No data.
Status : Deferred
Published: 2026-10-11T02:16:38.277
Modified: 2026-10-11T02:16:38.397
Link: CVE-2026-108700
No data.
OpenCVE Enrichment
No data.
Weaknesses