Impact
The vulnerability allows an authenticated back‑office user to change the sale state of a product by invoking the /admin-api/product/store-product/sale endpoint. This lack of authorization lets the attacker withdraw whole categories of items from sale or re‑enable them without proper permission checks, potentially causing unintended revenue loss or inventory errors. The weakness is a missing authorization flaw.
Affected Systems
The flaw exists in yshop‑crm versions up to and including 2.1.3 released by guchengwuyue. Users running any of these builds are susceptible. No specific product sub‑modules are limited; the flag applies to the StoreProductController globally.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity under current scoring criteria. The EPSS score of less than 1% shows a very low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. However, exploitation requires initial authentication as a back‑office user, which is typically granted to trusted staff. Once authenticated, an attacker can sequentially target product IDs to alter many items, presenting a system‑wide integrity risk if the authorization checks are not restored.
OpenCVE Enrichment