yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign leads from other employees to themselves by overwriting the ownerUserId field, with no access logging or quota validation to prevent bulk lead theft.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 11:30:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T17:43:45.260Z
Reserved: 2026-09-16T10:57:06.137Z
Link: CVE-2026-92459
Updated: 2026-09-16T17:43:36.973Z
Status : Received
Published: 2026-09-16T12:17:07.330
Modified: 2026-09-16T18:17:21.517
Link: CVE-2026-92459
No data.
OpenCVE Enrichment
No data.
Weaknesses