Product
PickMall Lilishop up to version 4.2.4 contains an improper authorization vulnerability in the Mobile Binding component, allowing remote attackers to manipulate the Username argument to bypass authorization controls.