Incorrect Access Control Vulnerability in Lilishop
CVE-2024-50654

7.5HIGH

Key Information:

Vendor

Pickmall

Status
Vendor
CVE Published:
15 November 2024

What is CVE-2024-50654?

The vulnerability in Lilishop versions up to 4.2.4 enables attackers to exploit incorrect access control mechanisms. By capturing and sending specific data packets during high concurrency scenarios, malicious users can collect more coupons than intended, violating quantity restrictions set by the platform. This exploitation poses significant risks to both user data integrity and the fairness of coupon distribution on the eCommerce site.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.