CVE-2024-50653: High severity crmeb crmeb vulnerability
CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50653?
CVE-2024-50653 has been categorized as a medium severity vulnerability due to its potential for abuse in coupon collection.
How do I fix CVE-2024-50653?
To fix CVE-2024-50653, upgrade to a version of CRMEB that is greater than 5.4.0 to ensure proper access controls are in place.
Who is affected by CVE-2024-50653?
Anyone using CRMEB versions 5.4.0 and below is affected by CVE-2024-50653, particularly in scenarios involving coupon claims.
What actions can malicious users take with CVE-2024-50653?
Malicious users can exploit CVE-2024-50653 to bypass restrictions and collect an unlimited number of coupons.
Is CVE-2024-50653 a common type of vulnerability?
CVE-2024-50653 represents a common access control vulnerability that can be exploited in web applications.