lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
References
Link | Resource |
---|---|
https://github.com/Yllxx03/CVE/blob/main/lilishop/CouponLogicVulnerability.md | Exploit Third Party Advisory |
https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50654 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-11-15 17:15
Updated : 2024-11-21 19:15
NVD link : CVE-2024-50654
Mitre link : CVE-2024-50654
CVE.ORG link : CVE-2024-50654
JSON object : View
Products Affected
pickmall
- lilishop
CWE