Impact
The vulnerability lies in the CrmInvoiceController's issueInvoice endpoint in yshop‑crm up to version 2.1.3. It is a missing authorization flaw (CWE‑862) that allows any authenticated back‑office user to issue invoices arbitrarily. An attacker can invoke the PUT /admin‑api/crm/invoice/issue endpoint without the required permissions, changing invoice status, inflating amounts, and triggering emails to addresses chosen by the attacker.
Affected Systems
This affects the yshop‑crm application provided by guchengwuyue up to version 2.1.3. No fix is publicly available, so users should check the pom.xml or current source to determine whether they are running a vulnerable release.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation at this time, and the flaw is not listed in CISA KEV. Nevertheless, because any authenticated back‑office user can tamper with financial records and send unauthorized emails, the risk is significant in environments where back‑office access is wide and invoice issuance is a critical business function. The likely attack vector is an authenticated back‑office session, inferred from the requirement of being logged in to call the endpoint.
OpenCVE Enrichment