PT-2024-20245 · Likeshop · Likeshop

Published

2024-02-29

·

Updated

2025-06-17

·

CVE-2024-24028

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Likeshop versions prior to 2.5.7
Description The issue allows attackers to view sensitive information. It is related to a Server Side Request Forgery (SSRF) vulnerability, which can be exploited via the avatar parameter in the UserLogic::updateWechatInfo() function.
Recommendations For versions prior to 2.5.7, update to version 2.5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the UserLogic::updateWechatInfo() function or the avatar parameter to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-24028

Affected Products

Likeshop