lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://github.com/Yllxx03/CVE/blob/main/lilishop/CouponLogicVulnerability.md | third party advisory exploit |
https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50654 | third party advisory exploit |