qbcore-framework / qb-truckrobbery

Armored Truck Robbery For QB-Core
GNU General Public License v3.0
26 stars 123 forks source link

[BUG] - Exploit #19

Closed GitMocha closed 1 year ago

GitMocha commented 1 year ago

Describe the bug

Was going through my server scripts looking for vulnerabilities, recently patched one for another script, and found one in qb-truckrobbery. Using XV-Dev tool to trigger events using the lua executor, i found that this can be triggered no matter what and you can just keep giving yourself money & bank security cards. even though whilst using the latest qb-truckrobbery there's distance checks it doesn't seem to really do anything.

Exploitable Event

TriggerServerEvent("AttackTransport:graczZrobilnapad", LootTime)

To Reproduce Steps to reproduce the behavior:

  1. open an executor, enter event, change loot time and trigger.
  2. See error - Nope.

Expected behavior

Screenshots

https://cdn.discordapp.com/attachments/1036106897054511145/1071531857969160252/Screenshot_3.png

Questions (please complete the following information):

Additional context N/A Screenshot_3