snowgears / shopbugs

Shop bug tracker
8 stars 4 forks source link

[BUG] CREATIVE EXPLOIT SERVERE #439

Closed Ek2100 closed 5 days ago

Ek2100 commented 1 month ago

Is there an existing issue for this?

Type of bug

Exploit

Environment

- Server Version: paper 1.21
- Shop Version: 1.9.0.1

Server startup log

does not effect exploit

Shop config files

does not effect exploit

Error log (if applicable)

No response

Bug description

When you are in the locked creative gamemode, you will be able to log out, and then log back in. And then you will be able to fly around with no restrictions and place items in your inventory / break items. Eg: if I had a dia block in my inv and than did the bug, I could place as many diamond blocks as I wanted

Steps to reproduce

  1. Open a shop
  2. For the cost of the item, click it with nothing to be in locked creative
  3. Log out and log back in
  4. You are now in creative and can effectively dupe valuable blocks

Expected behaviour

When relogging, the plugin should set you back to survival

Actual behaviour

The plugin keep you in creative when relogging

Other information

There are so many other issues with the locked creative I think it's best to just change it to a command. Someone on my server managed to obtain bedrock and end portal frames through the plugin however I am unsure the method they used. Just remove locked creative pls

OstlerDev commented 3 weeks ago

I was able to reproduce this, and have a fix that will be released in 1.9.1.0

OstlerDev commented 5 days ago

Released 1.9.1.0