PT-2026-93707 · Yshop-Crm · Yshop-Crm
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
yshop-crm versions prior to 2.1.4
Description
An authorization failure exists in the 'GET /admin-api/system/user/page' endpoint because the
@PreAuthorize annotation is commented out. This allows authenticated back-office users who lack the system:user:list permission to enumerate all users. Specifically, attackers possessing valid back-office credentials and a role with a data scope of ALL can retrieve the full user directory, including login names, nicknames, departments, email addresses, mobile numbers, and last login details.Recommendations
Update yshop-crm to version 2.1.4 or later.
Restrict access to the 'GET /admin-api/system/user/page' endpoint to prevent unauthorized user enumeration.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yshop-Crm