CVE-2026-92462 | guchengwuyue yshop-crm up to 2.1.3 CrmFlowController C09_crm_flow_delete_step.py deleteFlowStep improper authorization

SecurityVulns

A vulnerability was found in guchengwuyue yshop-crm up to 2.1.3. It has been declared as problematic. This issue affects the function deleteFlowStep of the file C09_crm_flow_delete_step.py of the component CrmFlowController. The manipulation results in improper authorization.

This vulnerability is cataloged as CVE-2026-92462. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More