CVE-2025-70981: SQL Injection
Published Feb 12, 2026
·Updated
CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.
Affected Software
2 affected components
Cordys CordysCRM
FIT2CLOUD Cordys Crm=1.4.1
Event History
Feb 12, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70981?
CVE-2025-70981 is considered a critical vulnerability due to its potential for SQL Injection, which can lead to unauthorized access to sensitive data.
2
How do I fix CVE-2025-70981?
To fix CVE-2025-70981, update CordysCRM to the latest version where the SQL injection vulnerability has been addressed.
3
What version of CordysCRM is affected by CVE-2025-70981?
CVE-2025-70981 affects CordysCRM version 1.4.1.
4
What kind of attack can be executed using CVE-2025-70981?
An attacker can execute a SQL Injection attack via the employee list query interface by manipulating the departmentIds parameter.
5
Is CVE-2025-70981 exploitable remotely?
Yes, CVE-2025-70981 is exploitable remotely, allowing attackers to exploit the vulnerability over the internet.