Skip to content

There is a Business logic vulnerability that can change the payment price. #5

@JrDw0

Description

@JrDw0

First we have selected seven items. The price is ¥6*7=¥42.
1
Then we can get the request package.
2
We changed the value of the parameter item_totals to 0.
3
So we can get free products like this.
4

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions