divios / DailyShop

Spigot plugin. Fully configurable shop with daily offers. NBT & multi-currency support and more!
https://www.spigotmc.org/resources/daily-shop-free-random-items-shop-customizable-items-timer-nbt-support-and-more.86907/
29 stars 15 forks source link

CRITICAL! Dupe money #35

Closed ArtifactyNight closed 3 years ago

ArtifactyNight commented 3 years ago

Player can sell item more than himself

How to do:

  1. Give diamond 40 ea
  2. Spam sell MAX button
  3. Click Yes

Player can sell diamond without losing the diamond

l3unnyAnoF4 commented 3 years ago

What version

divios commented 3 years ago

Hi! In what version are you in? Also free or premium? I am trying to replicate this and is not happening on my test server with the last premium version

divios commented 3 years ago

Alright that was not the issue, for some reason a check wasn't properly initialized and if a player adds items without buying them and leaves the server they mantain those items

ArtifactyNight commented 3 years ago

I'm testing with Premium version 3.5.3 He can make money from 10K to 190K with 40 diamond (I set diamond price is 600 per each) so i'm very sure this is can dupe

And he share a screen in discord and show how to do it

divios commented 3 years ago

mmm weird, i spammed max button too and it is working fine and the code looks fine too, i'm not really sure how is he doing it. Could you send me a video?

ArtifactyNight commented 3 years ago

for some reason sometime it's work and not work He testing with spam max button and cancel and spam again and click yes and loop it

.. maybe it's because 3rd party plugin?

Chestsort plugin? https://www.spigotmc.org/resources/chestsort-api.59773/

divios commented 3 years ago

Let me try it with that plugin

ArtifactyNight commented 3 years ago

oh nvm it's not max button but it's add button sorry about that

here is a videos https://streamable.com/x6puet

divios commented 3 years ago

What is your minecraft server's version?

ArtifactyNight commented 3 years ago

purpur 1.17.1 1394

l3unnyAnoF4 commented 3 years ago

I think he use version 3.5.2v1

divios commented 3 years ago

can you send me your .db file? I want to check it manually

ArtifactyNight commented 3 years ago

... I sincerely apologize
i'm using Premium 3.5.2 now i'm tested with Premium 3.5.3v3

it's have no issues now my bad 😭

l3unnyAnoF4 commented 3 years ago

I think he use version 3.5.2v1

I told you

l3unnyAnoF4 commented 3 years ago

I can do this in version 3.5.2v1.

https://streamable.com/riy7vq

ArtifactyNight commented 3 years ago

;-; i'm so sorry

divios commented 3 years ago

No problem, thanks both for reporting the issues :D