CVE-2024-50654

HIGH

lilishop <= 4.2.4 - Incorrect Access Control via Coupon Collection Packet Replay

Title source: llm
STIX 2.1

Description

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.

Scores

CVSS v3 7.5
EPSS 0.0156
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (1)
pickmall/lilishop < 4.2.4
Published Nov 15, 2024
Tracked Since Feb 18, 2026