Description
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain topology, step ordering, approver identifiers, and personal information including login names, nicknames, departments, email addresses, mobile numbers and last login IP addresses.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Sensitive Approval Workflow Data
Action: Apply Patch
AI Analysis

Impact

A missing authorization check in the GET /admin-api/crm/flow/flow-users endpoint allows any authenticated back‑office user to view approval workflow data, including approval chain topology, step ordering, approver identifiers, and personal information such as login names, nicknames, departments, emails, mobile numbers, and last login IP addresses. The vulnerability enables disclosure of sensitive internal data without privilege escalation or code execution, directly impacting confidentiality of personnel and operational information.

Affected Systems

The vulnerability applies to guchengwuyue's yshop-crm product, specifically all releases up to and including version 2.1.3. Users running any of these affected versions are at risk if they maintain a logged‑in back‑office session.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate risk, and the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability requires prior authentication with any back‑office user account, so attackers need valid credentials to gain the data. While the risk is moderate and the likelihood is low, the lack of a cleanup in the CISA KEV list does not mitigate the potential for data exposure to internal actors.

Generated by OpenCVE AI on September 18, 2026 at 06:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade yshop-crm to a version later than 2.1.3 that removes the missing authorization check on the /admin-api/crm/flow/flow-users endpoint.
  • Re‑enable or reinforce role‑based access controls so that only authorized personnel can access approval‑workflow data.
  • Audit back‑office user permissions and remove any unnecessary accounts that could exploit the exposed endpoint.

Generated by OpenCVE AI on September 18, 2026 at 06:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Guchengwuyue
Guchengwuyue yshop-crm
Vendors & Products Guchengwuyue
Guchengwuyue yshop-crm

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain topology, step ordering, approver identifiers, and personal information including login names, nicknames, departments, email addresses, mobile numbers and last login IP addresses.
Title yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Guchengwuyue Yshop-crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T13:34:52.609Z

Reserved: 2026-09-16T10:57:06.810Z

Link: CVE-2026-92461

cve-icon Vulnrichment

Updated: 2026-09-16T13:34:49.410Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T12:17:07.623

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-92461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses