CVE-2026-92461 PUBLISHED

yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain topology, step ordering, approver identifiers, and personal information including login names, nicknames, departments, email addresses, mobile numbers and last login IP addresses.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor guchengwuyue
Product yshop-crm
Versions Default: unaffected
  • affected from 0 to 2.1.3 (incl.)

Credits

  • Mingsheng Lin (lincoke) finder

References

Problem Types

  • Missing Authorization CWE