Loading market data...
← Back to CVE feed

CVE-2026-92459

MEDIUM CVSS 6.5 View on NVD ↗

Description

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign leads from other employees to themselves by overwriting the ownerUserId field, with no access logging or quota validation to prevent bulk lead theft.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Published: Sep 16, 2026 12:17 UTC Modified: Sep 16, 2026 18:17 UTC