{"id":"CVE-2026-10567","summary":"1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting","details":"A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the function Save of the file src/main/java/cn/cordys/crm/system/service/ModuleFormService.java of the component ModuleFormController. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.7.0 will fix this issue. The identifier of the patch is c87682afa8df79853299f75489c9d333f7bc5fce. Upgrading the affected component is recommended.","modified":"2026-08-12T15:31:10.488880Z","published":"2026-06-02T02:00:15.087Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-79","CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10567.json"},"references":[{"type":"WEB","url":"https://github.com/1Panel-dev/CordysCRM/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10567.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10567"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-10567"},{"type":"ADVISORY","url":"https://vuldb.com/submit/829316"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/367674"},{"type":"REPORT","url":"https://github.com/1Panel-dev/CordysCRM/issues/2233"},{"type":"REPORT","url":"https://vuldb.com/vuln/367674/cti"},{"type":"FIX","url":"https://github.com/1Panel-dev/CordysCRM/commit/c87682afa8df79853299f75489c9d333f7bc5fce"},{"type":"FIX","url":"https://github.com/1Panel-dev/CordysCRM/pull/2356"},{"type":"FIX","url":"https://github.com/1Panel-dev/CordysCRM/releases/tag/v1.7.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/1panel-dev/cordyscrm","events":[{"introduced":"d8ba007763a83f13897c8bb7c1cec53188b7655d"},{"fixed":"c87682afa8df79853299f75489c9d333f7bc5fce"},{"fixed":"7c2eadb9d76cc6613e6ccc7089c1c2f77480ecad"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"1.4.0"},{"last_affected":"1.4.0"},{"introduced":"1.4.1"},{"last_affected":"1.4.1"}]}}],"versions":["1.4.0","1.4.1","v1.6.2","v1.6.1","v1.6.0","v1.5.2","v1.5.1","v1.5.0","v1.4.1","v1.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10567.json","vanir_signatures_modified":"2026-08-12T15:31:10Z","vanir_signatures":[{"id":"CVE-2026-10567-227a04e8","signature_type":"Function","signature_version":"v1","source":"https://github.com/1panel-dev/cordyscrm/commit/c87682afa8df79853299f75489c9d333f7bc5fce","target":{"file":"backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java","function":"jackson2ObjectMapperBuilderCustomizer"},"deprecated":false,"digest":{"length":445,"function_hash":"268531600353582151246163503309634825220"}},{"deprecated":false,"digest":{"line_hashes":["39552555681519819189387037147769905448","251350195022106776886983067754661369744","45965048041040821694741255665393844153","94088371098056002821887869311948844183","254217025449220859722682014440749943913","323008323022811874092129056145067138141","44740514636723159633753781099826715128","61015434603556391711679583573628900240","333359280892804067620328767926291344950","265747610839340378484334957327677708931","58942325475207396321884924536250483554","282540525393533944297597144681895919237","313269510097358807310163056520956022181","225287783429731489671799643383219004463","32275434953731262630553471914023117618","265324251289332916155890401412783687713","18744409616202217698160852359591471275","132032598730935277598957983897534133274","90615326069007838700628674204908993936","159672745212706670003682564031355154174","173094764080546024817732512974621693650","271996939658003306207925676943741337696","289836497241667484882103762303030004200","297696124579921608161803891376881595536","145375660899068647807428379536872032926","213588714927290895947412294745517159155","36754399147974256052504292066187255475","115446728591475414005609566895079038815","184640788286126623453364494726640844626","234140577270823758213366940469681269739"],"threshold":0.9},"id":"CVE-2026-10567-397b0773","signature_type":"Line","signature_version":"v1","source":"https://github.com/1panel-dev/cordyscrm/commit/c87682afa8df79853299f75489c9d333f7bc5fce","target":{"file":"backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java"}},{"id":"CVE-2026-10567-a5718b56","signature_type":"Line","signature_version":"v1","source":"https://github.com/1panel-dev/cordyscrm/commit/7c2eadb9d76cc6613e6ccc7089c1c2f77480ecad","target":{"file":"backend/crm/src/main/java/cn/cordys/crm/approval/mapper/ExtApprovalInstanceMapper.java"},"deprecated":false,"digest":{"line_hashes":["300057984841402190454347434645157421473","220282082689875518599067250696579483920"],"threshold":0.9}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/1panel-dev/cordyscrm/commit/7c2eadb9d76cc6613e6ccc7089c1c2f77480ecad","target":{"file":"backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalActionService.java"},"deprecated":false,"digest":{"line_hashes":["264654641498068565163148758720303247925","326319180140202264514769382317587271969","207053217838931752325967036852955105498","49388233016336645149709755269713248646","155526835061659021775855202167188289841","118485121350428657810771187351667871175","250469855315514493926495268485789081327","152047592666521901160313551738195476006","85252776332415329353061921149240507081","262604562922142974165366710064216355354","262475088046163131975242340744163792859","306657523969764582489273493365329137111","191712704461071390710765108468701459976","323168859459042983681696155917142195420","205956062299661666358570989598739035348"],"threshold":0.9},"id":"CVE-2026-10567-cff5f585"},{"signature_version":"v1","source":"https://github.com/1panel-dev/cordyscrm/commit/c87682afa8df79853299f75489c9d333f7bc5fce","target":{"function":"deserialize","file":"backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java"},"deprecated":false,"digest":{"function_hash":"172719391140758691532530812452954467540","length":198},"id":"CVE-2026-10567-d681b7ec","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"}]}