PT-2024-34381 · Crmeb · Crmeb

CVE-2024-50653

·

Published

2024-11-15

·

Updated

2024-11-20

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: CRMEB versions prior to 5.4.0
Description: The issue allows users to bypass the front-end restriction of only being able to claim coupons once. This can be achieved by capturing packets and sending a large number of data packets for coupon collection, resulting in unlimited coupon collection.
Recommendations: For CRMEB versions prior to 5.4.0, update to version 5.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the coupon collection feature to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-50653

Affected Products

Crmeb