Impact
yshop-crm through version 2.1.3 contains an authorization bypass on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back‑office user to view the system‑wide audit trail. The vulnerability, classified as CWE-862, permits unauthenticated access to sensitive operational data such as operator names, display nicknames, client IP addresses, User‑Agent strings, request URLs, action details, and customer identifiers, leading to a confidentiality breach.
Affected Systems
The affected product is yshop‑crm from guchengwuyue, with versions up to and including 2.1.3. Users running these versions should verify the firmware version and consider immediate upgrade.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Attackers require only authenticated back‑office access to issue a simple GET request; no special network privileges are needed, making the exploit straightforward once inside the trusted environment.
OpenCVE Enrichment