CVE-2024-50654

HIGH

Pickmall Lilishop < 4.2.4 - Origin Validation Error

Title source: rule

Description

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.

Scores

CVSS v3 7.5
EPSS 0.0027
EPSS Percentile 50.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-346
Status published

Affected Products (1)

pickmall/lilishop < 4.2.4

Timeline

Published Nov 15, 2024
Tracked Since Feb 18, 2026