Description
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign leads from other employees to themselves by overwriting the ownerUserId field, with no access logging or quota validation to prevent bulk lead theft.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Lead Reassignment
Action: Immediate Patch
AI Analysis

Impact

A missing authorization flaw in yshop‑crm allows authenticated back‑office users to claim sales leads through the receiveCustomer endpoint. The missing checks let an attacker overwrite the ownerUserId field, enabling them to reassign leads from other employees to themselves and potentially theft a large number of leads.

Affected Systems

The vulnerability affects guchengwuyue yshop‑crm up to and including version 2.1.3. Systems running these or earlier releases are impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high risk, and the EPSS score of less than 1% suggests that exploitation is not highly probable at the present time. The flaw is not listed in CISA’s KEV catalog. Based on the description it is inferred that the attacker must be an authenticated back‑office user; the vulnerability does not require remote code execution or system compromise beyond authorized access to the lead‑claim endpoint, but it can be leveraged to divert leads and cause significant business disruption.

Generated by OpenCVE AI on September 18, 2026 at 06:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest yshop‑crm release that includes the missing authorization fix. If a patch is not immediately available, restrict the lead‑claim endpoint to administrators or apply role‑based access controls that prevent ordinary back‑office users from calling it.
  • Enable or implement audit logging for all lead reassignment actions so that any unauthorized changes can be detected and traced back to a user.
  • Introduce rate limiting or quota checks on the lead‑claim operation to prevent bulk lead theft and reduce the potential impact of the vulnerability.

Generated by OpenCVE AI on September 18, 2026 at 06:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Guchengwuyue
Guchengwuyue yshop-crm
Vendors & Products Guchengwuyue
Guchengwuyue yshop-crm

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign leads from other employees to themselves by overwriting the ownerUserId field, with no access logging or quota validation to prevent bulk lead theft.
Title yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Guchengwuyue Yshop-crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T17:43:45.260Z

Reserved: 2026-09-16T10:57:06.137Z

Link: CVE-2026-92459

cve-icon Vulnrichment

Updated: 2026-09-16T17:43:36.973Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T12:17:07.330

Modified: 2026-09-24T20:48:01.433

Link: CVE-2026-92459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses