CVE-2026-15753
MEDIUMzhinianboke xianyu-auto-reply review approve trusting http permission methods on the server side
Title source: cnaDescription
A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can lead to trusting http permission methods on the server side. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 19fc3282a1bb78a05c34945c088525d20e081cbd. It is best practice to apply a patch to resolve this issue.
References (7)
Core 7
Core References
Vdb Entry vdb-entry
VDB-378335 | zhinianboke xianyu-auto-reply review approve trusting http permission methods on the server side
https://vuldb.com/vuln/378335
Signature, Permissions Required signature
permissions-required
VDB-378335 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/378335/cti
Third Party Advisory third-party-advisory
CVE-2026-15753 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15753
Third Party Advisory third-party-advisory
Submit #856719 | zhinianboke xianyu-auto-reply main at or before 04580d6490b4731d0055f29736930d8cc59b60d6 CWE-650 Trusting HTTP Permission Methods on the Server Side
https://vuldb.com/submit/856719
Exploit exploit
issue-tracking
https://github.com/zhinianboke/xianyu-auto-reply/issues/192
Patch patch
https://github.com/zhinianboke/xianyu-auto-reply/commit/19fc3282a1bb78a05c34945c088525d20e081cbd
Product product
https://github.com/zhinianboke/xianyu-auto-reply/
Scores
CVSS v3
5.4
EPSS
0.0026
EPSS Percentile
17.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-650
Status
published
Products (1)
zhinianboke/xianyu-auto-reply
Published
Jul 14, 2026
Tracked Since
Jul 15, 2026