ZeroHour

CVE-2024-50654

PoC ×2
CVSS 3.1
7.5 high
EPSS
2%p75
Published
()
Modified
Description

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.

Vendors
pickmall
Products
lilishop
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.