Описание
lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.2.4 (включая)
cpe:2.3:a:pickmall:lilishop:*:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.00205
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-346
Связанные уязвимости
CVSS3: 7.5
github
около 1 года назад
lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
EPSS
Процентиль: 43%
0.00205
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-346