Impact
A missing authorization flaw in yshop‑crm allows authenticated back‑office users to claim sales leads through the receiveCustomer endpoint. The missing checks let an attacker overwrite the ownerUserId field, enabling them to reassign leads from other employees to themselves and potentially theft a large number of leads.
Affected Systems
The vulnerability affects guchengwuyue yshop‑crm up to and including version 2.1.3. Systems running these or earlier releases are impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high risk, and the EPSS score of less than 1% suggests that exploitation is not highly probable at the present time. The flaw is not listed in CISA’s KEV catalog. Based on the description it is inferred that the attacker must be an authenticated back‑office user; the vulnerability does not require remote code execution or system compromise beyond authorized access to the lead‑claim endpoint, but it can be leveraged to divert leads and cause significant business disruption.
OpenCVE Enrichment