Impact
The vulnerability is caused by a missing authorization check in the GET /admin-api/system/user/page endpoint, where the @PreAuthorize annotation has been commented out. As a result, any authenticated back‑office user lacking the system:user:list permission can enumerate the full user directory, including login names, nicknames, departments, email addresses, mobile numbers, and last login timestamps. An attacker who has valid back‑office credentials and a role with data scope ALL can exploit this to gain detailed information about all users, providing a basis for social‑engineering attacks or identity theft.
Affected Systems
This issue affects yshop‑crm by guchengwuyue up to version 2.1.3. No confirmation is available about whether versions beyond 2.1.3 address the issue.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of <1% suggests that exploitation is currently considered unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Attack is possible only after authentication to the back‑office interface and requires a user role with data scope ALL. The primary attack vector is therefore an authenticated internal user exploiting a missing authorization check. While the likelihood of widespread exploitation is low, the impact of granting full user information to unauthorized roles warrants prompt remediation.
OpenCVE Enrichment