Description
yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display nicknames, client IP addresses, User-Agent strings, request URLs, action details, and customer identifiers without proper permission checks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Sep 2026 11:30:00 +0000
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T11:07:29.492Z
Reserved: 2026-09-16T10:57:06.466Z
Link: CVE-2026-92460
No data.
Status : Deferred
Published: 2026-09-16T12:17:07.480
Modified: 2026-09-16T19:47:01.197
Link: CVE-2026-92460
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-862
Missing Authorization