VYPR
High severity7.5NVD Advisory· Published Nov 15, 2024· Updated Jun 17, 2026

CVE-2024-50653

CVE-2024-50653

Description

CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Crmeb/Crmeb3 versions
    cpe:2.3:a:crmeb:crmeb:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:crmeb:crmeb:*:*:*:*:*:*:*:*range: <=5.4.0
    • (no CPE)
    • (no CPE)range: <=5.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.