CyberRota Analysis
AI-GeneratedCordysCRM versions prior to 1.7.2 are vulnerable due to improperly secured SSE endpoints, allowing unauthenticated users to access and manipulate another user's workflow events and notifications. The impact includes unauthorized data exposure and potential disruption of user sessions, making this a critical concern for organizations utilizing CordysCRM for customer relationship management. All users of affected versions should prioritize upgrading to 1.7.2 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2.