Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92456— yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints

Quick assessment

Affected
guchengwuyue yshop-crm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy.

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92456

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared Redis keys controlling customer auto-recycling behavior, causing mass customer data deletion, disabling lead recycling, or blocking customer creation across the deployment.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
guchengwuyue yshop-crm 0 ~ 2.1.3 -

II. Public POCs for CVE-2026-92456

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92456

登录查看更多情报信息。

Vendor Advisories for CVE-2026-92456 (1)

Proof of Concept for CVE-2026-92456 (1)

Other References for CVE-2026-92456 (5)

Same Patch Batch · guchengwuyue · 2026-09-16 · 9 CVEs total

CVE-2026-92460 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing
CVE-2026-92462 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlowStep
CVE-2026-92463 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on System User Listi
CVE-2026-92459 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint
CVE-2026-92457 6.5 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice
CVE-2026-92461 4.3 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint
CVE-2026-92455 4.3 MEDIUM yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints
CVE-2026-92458 4.3 MEDIUM yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale

IV. Related Vulnerabilities

V. Comments for CVE-2026-92456

No comments yet


Leave a comment