PT-2026-93703 · Yshop-Crm · Yshop-Crm
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
yshop-crm versions prior to 2.1.4
Description
Authenticated back-office users can claim sales leads without proper permission checks. By invoking the 'receiveCustomer' endpoint in the
CrmCluesController, an attacker can reassign leads from other employees to themselves by overwriting the ownerUserId field. The system lacks access logging and quota validation, which could allow for bulk lead theft.Recommendations
Update yshop-crm to version 2.1.4 or later.
Restrict access to the
receiveCustomer endpoint in the CrmCluesController to minimize the risk of unauthorized lead reassignment.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yshop-Crm