yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display nicknames, client IP addresses, User-Agent strings, request URLs, action details, and customer identifiers without proper permission checks.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 11:30:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T19:26:47.471Z
Reserved: 2026-09-16T10:57:06.466Z
Link: CVE-2026-92460
Updated: 2026-09-17T18:40:08.443Z
Status : Deferred
Published: 2026-09-16T12:17:07.480
Modified: 2026-09-17T20:18:55.860
Link: CVE-2026-92460
No data.
OpenCVE Enrichment
No data.
Weaknesses