CVE-2026-76899 | 1Panel-dev CordysCRM up to 1.7.3 Sort Request CommonMapper.xml SortRequest.getName sql injection
A vulnerability was found in 1Panel-dev CordysCRM up to 1.7.3. It has been rated as problematic. The impacted element is the function SortRequest.getName of the file CommonMapper.xml of the component Sort Request. Performing a manipulation of the argument Name results in sql injection.
This vulnerability is cataloged as CVE-2026-76899. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More