CVE-2026-92457

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
16/09/2026
Last modified:
23/09/2026

Description

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required permissions to modify invoice status, inflate contract invoiced amounts with attacker-chosen values, and trigger invoice emails to arbitrary addresses.