webProeasy
Lab 216 — ShelfWave — IDOR Price Manipulation in Checkout
hackadvisor
Task: ShelfWave checkout lets the browser submit product IDs, quantities, and prices for cart items. Solution: add the expensive Enterprise Vault Access product, then POST checkout JSON with its price changed to 0.01.
$ ls tags/ techniques/
idor_exploitationparameter_tamperingcheckout_price_manipulation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 193 — ShopNova — Price Manipulation in Checkout API— hackadvisor
- [web][Pro]Lab 61 — OrderNova — Negative Quantity Price Manipulation— hackadvisor
- [web][Pro]Lab 14 — SoundMart — Race Condition in Coupon Redemption— hackadvisor
- [web][Pro]Lab 116 — InsightForge — IDOR via Undocumented Internal API— hackadvisor
- [web][Pro]Lab 21 — ShelfSpace — Stored XSS in Product Description Editor— hackadvisor