yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display nicknames, client IP addresses, User-Agent strings, request URLs, action details, and customer identifiers without proper permission checks.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 11:30:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T11:07:29.492Z
Reserved: 2026-09-16T10:57:06.466Z
Link: CVE-2026-92460
No data.
Status : Received
Published: 2026-09-16T12:17:07.480
Modified: 2026-09-16T12:17:07.480
Link: CVE-2026-92460
No data.
OpenCVE Enrichment
No data.
Weaknesses