yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.3%
probabilidad de explotación
0.3%top 80% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /admin-api/crm/customer/send-sms and POST /admin-api/crm/customer/send-mail with arbitrary customerIds, templateCode, and templateParams to deliver unauthorized messages through the organization's SMS and email channels.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
guchengwuyue · yshop-crmPoCs públicas encontradas — 2
cve_referencegithub.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C02_crm_customer_send_mail.pyno verificadocve_referencegithub.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C01_crm_customer_send_sms.pyno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/guchengwuyue/yshop-crmhttps://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/pom.xml#L30https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/controller/admin/crmcustomer/CrmCustomerController.java#L122https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/service/crmcustomer/CrmCustomerServiceImpl.java#L264https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C01_crm_customer_send_sms.pyhttps://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C02_crm_customer_send_mail.pyhttps://www.vulncheck.com/advisories/yshop-crm-through-2.1.3-missing-authorization-via-crm-customer-messaging-endpoints