Impact
A missing authorization check in the GET /admin-api/crm/flow/flow-users endpoint allows any authenticated back‑office user to view approval workflow data, including approval chain topology, step ordering, approver identifiers, and personal information such as login names, nicknames, departments, emails, mobile numbers, and last login IP addresses. The vulnerability enables disclosure of sensitive internal data without privilege escalation or code execution, directly impacting confidentiality of personnel and operational information.
Affected Systems
The vulnerability applies to guchengwuyue's yshop-crm product, specifically all releases up to and including version 2.1.3. Users running any of these affected versions are at risk if they maintain a logged‑in back‑office session.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate risk, and the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability requires prior authentication with any back‑office user account, so attackers need valid credentials to gain the data. While the risk is moderate and the likelihood is low, the lack of a cleanup in the CISA KEV list does not mitigate the potential for data exposure to internal actors.
OpenCVE Enrichment