CVE-2024-50654

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pickmall:lilishop:*:*:*:*:*:*:*:*

History

21 Nov 2024, 19:15

Type Values Removed Values Added
CWE CWE-346

20 Nov 2024, 15:27

Type Values Removed Values Added
CPE cpe:2.3:a:pickmall:lilishop:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE NVD-CWE-noinfo
References () https://github.com/Yllxx03/CVE/blob/main/lilishop/CouponLogicVulnerability.md - () https://github.com/Yllxx03/CVE/blob/main/lilishop/CouponLogicVulnerability.md - Exploit, Third Party Advisory
References () https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50654 - () https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50654 - Exploit, Third Party Advisory
First Time Pickmall
Pickmall lilishop

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) lilishop &lt;=4.2.4 es vulnerable a un control de acceso incorrecto, que puede permitir a los atacantes obtener cupones más allá del límite de cantidad al capturar y enviar los paquetes de datos para la recolección de cupones en alta concurrencia.

15 Nov 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 17:15

Updated : 2024-11-21 19:15


NVD link : CVE-2024-50654

Mitre link : CVE-2024-50654

CVE.ORG link : CVE-2024-50654


JSON object : View

Products Affected

pickmall

  • lilishop
CWE
NVD-CWE-noinfo CWE-346

Origin Validation Error