Beveiligingsadvies

CVE-2026-92459

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-16 11:07:28
Laatst bijgewerkt 2026-09-16 17:43:45
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign leads from other employees to themselves by overwriting the ownerUserId field, with no access logging or quota validation to prevent bulk lead theft.