Description
yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display nicknames, client IP addresses, User-Agent strings, request URLs, action details, and customer identifiers without proper permission checks.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Sep 2026 11:30:00 +0000
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T11:07:29.492Z
Reserved: 2026-09-16T10:57:06.466Z
Link: CVE-2026-92460
No data.
Status : Received
Published: 2026-09-16T12:17:07.480
Modified: 2026-09-16T12:17:07.480
Link: CVE-2026-92460
No data.
OpenCVE Enrichment
No data.
Weaknesses