Pickmall

Lilishop

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 06.10.2026 02:30:15
  • Zuletzt bearbeitet 06.10.2026 15:04:52

A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is po...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 06.10.2026 02:00:09
  • Zuletzt bearbeitet 08.10.2026 03:16:33

A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorizatio...

Exploit
  • EPSS 1.56%
  • Veröffentlicht 15.11.2024 17:15:20
  • Zuletzt bearbeitet 21.11.2024 19:15:11

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.