Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92455— yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints

Quick assessment

Affected
guchengwuyue yshop-crm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /admin-api/crm/customer/s

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92455

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /admin-api/crm/customer/send-sms and POST /admin-api/crm/customer/send-mail with arbitrary customerIds, templateCode, and templateParams to deliver unauthorized messages through the organization's SMS and email channels.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
guchengwuyue yshop-crm 0 ~ 2.1.3 -

II. Public POCs for CVE-2026-92455

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92455

登录查看更多情报信息。

Vendor Advisories for CVE-2026-92455 (1)

Proof of Concept for CVE-2026-92455 (2)

Other References for CVE-2026-92455 (4)

Same Patch Batch · guchengwuyue · 2026-09-16 · 9 CVEs total

CVE-2026-92456 7.1 HIGH yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoint
CVE-2026-92460 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing
CVE-2026-92462 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlowStep
CVE-2026-92463 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on System User Listi
CVE-2026-92459 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint
CVE-2026-92457 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice
CVE-2026-92461 4.3 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint
CVE-2026-92458 4.3 MEDIUM yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale

IV. Related Vulnerabilities

V. Comments for CVE-2026-92455

No comments yet


Leave a comment