Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108701

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Oct 11, 2026
Vendor unknown

Description

1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability in the ContractController sortModule handler for POST /contract/sort, which lacks any permission annotation. Authenticated users without contract update permission can supply a dragNodeId, stage and field values to modify any contract, including contracts in other organizations.

References