PT-2026-93705 · Yshop-Crm · Yshop-Crm

·

CVE-2026-92461

·

Published

2026-09-16

·

Updated

2026-09-23

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions yshop-crm versions prior to 2.1.4
Description A missing authorization issue exists in the 'GET /admin-api/crm/flow/flow-users' endpoint. This allows any authenticated back-office user to access sensitive approval workflow data, including approval chain topology, step ordering, and approver identifiers. Additionally, personal information such as login names, nicknames, departments, email addresses, mobile numbers, and last login IP addresses can be retrieved.
Recommendations Update to version 2.1.4 or later. Restrict access to the 'GET /admin-api/crm/flow/flow-users' endpoint to authorized personnel only.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92461

Affected Products

Yshop-Crm