Critical severity9.8NVD Advisory· Published Feb 12, 2026· Updated Jun 17, 2026
CVE-2025-70981
CVE-2025-70981
Description
CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: =1.4.1
Patches
Vulnerability mechanics
References
1- github.com/Tomikun2/SQL-Injection-in-CordysCRM/blob/main/README.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.