CVE Vulnerabilities

CVE-2024-50654

Published: Nov 15, 2024 | Modified: Nov 20, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.

Affected Software

Name Vendor Start Version End Version
Lilishop Pickmall * 4.2.4 (including)

References