Impact
The vulnerability lies in the lack of authorization checks on the sendSms and send‑mail endpoints of yshop‑crm’s CrmCustomerController. Any authenticated back‑office user can POST to /admin-api/crm/customer/send‑sms or /admin-api/crm/customer/send‑mail, specifying arbitrary customerIds, templateCode and templateParams. This allows the attacker to send SMS and email messages to any customer without consent, potentially leading to spam, phishing or other social‑engineering attacks. The weakness is a classic missing authorization flaw (CWE‑862).
Affected Systems
Affected products include guchengwuyue’s yshop‑crm up to and including version 2.1.3. The issue is specific to this version; later releases are not reported to be vulnerable. An organization running an unpatched instance of yshop‑crm with any staff possessing back‑office credentials is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, while the EPSS of less than 1% suggests a low probability of exploitation in the wild. Because the bug requires a legitimate back‑office login, the attack surface is limited to users with valid credentials, and an attacker would need to subvert or coerce such a user. The vulnerability is not currently listed in the CISA KEV catalog. Nonetheless, organizations should view this as a risk to message integrity and customer trust.
OpenCVE Enrichment