Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-92457

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Sep 16, 2026
Vendor unknown

Description

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required permissions to modify invoice status, inflate contract invoiced amounts with attacker-chosen values, and trigger invoice emails to arbitrary addresses.

References