Missing Authorization in StoreProductController of yshop-crm by Yixiang
CVE-2026-92458
Key Information:
- Vendor
Guchengwuyue
- Status
- Vendor
- CVE Published:
- 16 September 2026
Badges
What is CVE-2026-92458?
In yshop-crm version 2.1.3, a flaw exists in the StoreProductController where the onSale handler does not enforce proper authorization checks. This vulnerability allows authenticated back-office users to alter the sale status of products by accessing the /admin-api/product/store-product/sale endpoint with sequential product IDs. Consequently, this oversight can enable attackers to unintentionally withdraw entire product catalogs from sale or re-enable products previously withdrawn, ultimately compromising the integrity of the product management system.
Affected Version(s)
yshop-crm 0 <= 2.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
