{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/yshop-crm--2.1.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yshop-crm:yshop-crm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-92456"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["yshop-crm (\u003c= 2.1.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["yshop-crm"],"content_html":"\u003cp\u003eyshop-crm versions up to and including 2.1.3 contain a critical authorization flaw within the CrmCustomerController. The application fails to enforce proper access control checks on the saveRedisSet and getRedisSet endpoints. This vulnerability allows any user with authenticated back-office access to perform unauthorized read and write operations on critical Redis keys. These keys govern installation-wide business logic, specifically lead-allocation and customer auto-recycling policies. By manipulating these settings, an attacker can disrupt the core functionality of the CRM, leading to the deletion of customer records, the disabling of lead recycling mechanisms, or a denial-of-service state that prevents the creation of new customers across the entire deployment. Defenders should prioritize auditing logs for unauthorized access to these specific administrative endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized modification of business-critical CRM settings. The primary impact includes the potential for mass deletion of customer data, prolonged business process disruption through the disabling of lead recycling, and an application-wide denial-of-service condition where customer creation becomes impossible. The scope of impact is limited to the CRM's internal data and business operations but poses a significant risk to organizational data integrity and service availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit application logs for frequent or unauthorized HTTP POST/GET requests directed at the saveRedisSet and getRedisSet endpoints within the CrmCustomerController.\u003c/li\u003e\n\u003cli\u003eImplement strict role-based access control (RBAC) validation for administrative CRM functions to prevent non-privileged users from interacting with backend controller logic.\u003c/li\u003e\n\u003cli\u003eMonitor Redis-related application calls for unexpected key modifications that deviate from standard administrative workflows.\u003c/li\u003e\n\u003cli\u003eIf a patch becomes available for yshop-crm, prioritize testing and deployment to all production instances immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T13:49:15Z","date_published":"2026-09-16T13:49:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-yshop-crm-auth-bypass/","summary":"An authorization bypass vulnerability in yshop-crm versions 2.1.3 and earlier allows authenticated users to manipulate Redis-based customer policies, leading to service disruption and data loss.","title":"Authorization Bypass in yshop-crm CrmCustomerController","url":"https://feed.craftedsignal.io/briefs/2026-09-yshop-crm-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Yshop-Crm (\u003c= 2.1.3)","version":"https://jsonfeed.org/version/1.1"}