CVE-2026-92457EPSS p35.0%
CVE-2026-92457CVE-2026-92457
Description
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required permissions to modify invoice status, inflate contract invoiced amounts with attacker-chosen values, and trigger invoice emails to arbitrary addresses.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
| EPSS | 0.43% probability of exploitation · percentile 35.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-23 |