CVE-2026-16223: 1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery
A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit Endpoint. Executing a manipulation of the argument appSecret can lead to server-side request forgery. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16223?
The severity of CVE-2026-16223 is categorized as medium with a score of 6.3.
What type of vulnerability is CVE-2026-16223?
CVE-2026-16223 is a server-side request forgery (SSRF) vulnerability.
How do I fix CVE-2026-16223?
To fix CVE-2026-16223, ensure you update to a patched version of 1Panel-dev CordysCRM that addresses this vulnerability.
What component is affected by CVE-2026-16223?
CVE-2026-16223 affects the Third Party Edit Endpoint in the IntegrationConfigService.java file of 1Panel-dev CordysCRM.
What is the impact of CVE-2026-16223?
Exploiting CVE-2026-16223 can allow attackers to manipulate the appSecret argument, potentially leading to unauthorized access to internal resources.