CVE-2024-50654
HIGHPickmall Lilishop < 4.2.4 - Origin Validation Error
Title source: ruleDescription
lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
Scores
CVSS v3
7.5
EPSS
0.0027
EPSS Percentile
50.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-346
Status
published
Affected Products (1)
pickmall/lilishop
< 4.2.4
Timeline
Published
Nov 15, 2024
Tracked Since
Feb 18, 2026