CVE-2024-24028

Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information via the avatar parameter in function UserLogic::updateWechatInfo.
Configurations

Configuration 1 (hide)

cpe:2.3:a:likeshop:likeshop:*:*:*:*:*:*:*:*

History

17 Jun 2025, 13:02

Type Values Removed Values Added
References () https://thanhlo.substack.com/p/khai-thac-lo-hong-cve-2024-24028 - () https://thanhlo.substack.com/p/khai-thac-lo-hong-cve-2024-24028 - Broken Link
CPE cpe:2.3:a:likeshop:likeshop:*:*:*:*:*:*:*:*
First Time Likeshop likeshop
Likeshop

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://thanhlo.substack.com/p/khai-thac-lo-hong-cve-2024-24028 - () https://thanhlo.substack.com/p/khai-thac-lo-hong-cve-2024-24028 -

07 Nov 2024, 22:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CWE CWE-918
Summary
  • (es) La vulnerabilidad de Server Side Request Forgery (SSRF) en Likeshop anterior a 2.5.7 permite a los atacantes ver información confidencial a través del parámetro avatar en la función UserLogic::updateWechatInfo.

21 Mar 2024, 02:52

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-21 02:52

Updated : 2025-06-17 13:02


NVD link : CVE-2024-24028

Mitre link : CVE-2024-24028

CVE.ORG link : CVE-2024-24028


JSON object : View

Products Affected

likeshop

  • likeshop
CWE
CWE-918

Server-Side Request Forgery (SSRF)