lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
References
Link | Resource |
---|---|
https://github.com/Yllxx03/CVE/blob/main/lilishop/CouponLogicVulnerability.md | Exploit Third Party Advisory |
https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50654 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-346 |
20 Nov 2024, 15:27
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:pickmall:lilishop:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | NVD-CWE-noinfo | |
References | () https://github.com/Yllxx03/CVE/blob/main/lilishop/CouponLogicVulnerability.md - Exploit, Third Party Advisory | |
References | () https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50654 - Exploit, Third Party Advisory | |
First Time |
Pickmall
Pickmall lilishop |
18 Nov 2024, 17:11
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Nov 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-15 17:15
Updated : 2024-11-21 19:15
NVD link : CVE-2024-50654
Mitre link : CVE-2024-50654
CVE.ORG link : CVE-2024-50654
JSON object : View
Products Affected
pickmall
- lilishop
CWE