Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108702

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Oct 11, 2026
Vendor unknown

Description

1Panel-dev CordysCRM through 1.9.3 lacks a PROCESS_SETTING permission check on POST /approval-flow/webhook/test, allowing any authenticated user to trigger server-side requests to attacker-supplied URLs. Attackers can redirect GET requests from a controlled host to bypass SSRFValidator and probe internal addresses through success or failure results.

References