VYPR

yshop-crm

by Guchengwuyue

CVEs (3)

  • CVE-2026-92460MedSep 16, 2026
    risk 0.42cvss 6.5epss

    yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display…

  • CVE-2026-92459MedSep 16, 2026
    risk 0.42cvss 6.5epss

    yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign…

  • CVE-2026-92457MedSep 16, 2026
    risk 0.42cvss 6.5epss

    yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required…