Executive brief
CordysCRM is an open-source AI-powered customer relationship management system. The file preview endpoints allow unauthenticated access and perform no authorization checks, enabling attackers to download files uploaded by users in other organizations by guessing file identifiers. This could expose sensitive business data across organizations.
Technical details
The /attachment/preview/{id} and /pic/preview/{id} endpoints are configured as anonymous in ShiroFilter and call AttachmentService.getResource, which performs only a bare primary-key lookup without checking ownership, organization membership, or permissions. An attacker can predict or discover file IDs (generated by IDGenerator.nextStr) and retrieve files belonging to other organizations. The fix in version 1.7.4 introduces a FileAccessAuthFilter to enforce proper authorization.
Affected products
- 1Panel CordysCRM prior to 1.7.4
Timeline
- 2026-09-18: disclosed
- 2026-07-10: patched: Fix released in version 1.7.4