Vulnerability Description
yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared Redis keys controlling customer auto-recycling behavior, causing mass customer data deletion, disabling lead recycling, or blocking customer creation across the deployment.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C04_crm_cust
- https://github.com/guchengwuyue/yshop-crm
- https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2
- https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2
- https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2
- https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2
- https://www.vulncheck.com/advisories/yshop-crm-through-2.1.3-missing-authorizati
FAQ
What is CVE-2026-92456?
CVE-2026-92456 is a vulnerability with a CVSS score of 7.1 (HIGH). yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installati...
How severe is CVE-2026-92456?
CVE-2026-92456 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-92456?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.