PT-2026-93703 · Yshop-Crm · Yshop-Crm

·

CVE-2026-92459

·

Published

2026-09-16

·

Updated

2026-09-23

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions yshop-crm versions prior to 2.1.4
Description Authenticated back-office users can claim sales leads without proper permission checks. By invoking the 'receiveCustomer' endpoint in the CrmCluesController, an attacker can reassign leads from other employees to themselves by overwriting the ownerUserId field. The system lacks access logging and quota validation, which could allow for bulk lead theft.
Recommendations Update yshop-crm to version 2.1.4 or later. Restrict access to the receiveCustomer endpoint in the CrmCluesController to minimize the risk of unauthorized lead reassignment.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92459

Affected Products

Yshop-Crm