QuickShop-Hikari - A powerful, user-friendly and reliable ChestShop plugin [1.20-1.21] icon

QuickShop-Hikari - A powerful, user-friendly and reliable ChestShop plugin [1.20-1.21] -----

A shop plugin that allows players to easily sell/buy any items from container without any commands.



Security patch to Per-player permission system exploit
Fixed a security issue:

  • Missing store ownership check when a player modifies a user's store permissions using the /qs permission command. This allows the user to take over arbitrary store permissions, including the administrator store.
    • This patch will not revoke permissions, you will need to do a check on the store's already set Per-player permissions property to avoid pre-existing exploits.
    • For past versions, you can disable the command interface for the per-player permission system to avoid new exploits /lp group default permission set quickshop.permission false.
However, upgrading is still recommended.

Considering that this security vulnerability allows for store privilege escalation (including unlimited stores, aka AdminShop) and allows for the modification of store transaction contents, prices, and disruption of the server's economic system, we strongly recommend that you plan an update immediately and utilize LuckPerms through the guide to disable this feature before you maintain it.
----------, Jan 3, 2024
Resource Information
Author:
----------
Total Downloads: 39,673
First Release: Feb 18, 2022
Last Update: Aug 25, 2024
Category: ---------------
All-Time Rating:
27 ratings
Find more info at quickshop-community.github.io...
Version -----
Released: --------------------
Downloads: ------
Version Rating:
----------------------
-- ratings