Description


CordysCRM through 1.9.3 contains an authorization bypass vulnerability that allows low-privileged authenticated users to skip permission checks by setting the owner field to their own user id. Attackers can send requests to the follow/record/add endpoints to add follow-up records and overwrite follow_time and follower on any known customer, clue or opportunity.

Related CPE's


Could not find any relations

Weaknesses



CWE-639

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

4.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-11T02:16:38.980Z

1 hour ago

Last modified

2026-10-11T02:16:39.107Z

1 hour ago