CVE-2026-92459 | guchengwuyue yshop-crm up to 2.1.3 lead-claim endpoint C06_crm_clues_receive.py CrmCluesController.receiveCustomer ownerUserId authorization

SecurityVulns

A vulnerability identified as problematic has been detected in guchengwuyue yshop-crm up to 2.1.3. The impacted element is the function CrmCluesController.receiveCustomer of the file C06_crm_clues_receive.py of the component lead-claim endpoint. Performing a manipulation of the argument ownerUserId results in missing authorization.

This vulnerability is reported as CVE-2026-92459. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More