webProeasy
Lab 61 — OrderNova — Negative Quantity Price Manipulation
hackadvisor
Task: E-commerce food ordering platform with wallet balance, premium item costs more than available funds. Solution: Bypassed client-side validation by sending negative quantity via API to offset total price below wallet balance.
$ ls tags/ techniques/
business_logic_bypassapi_manipulationserver_side_validation_bypassnegative_quantity_exploitation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 193 — ShopNova — Price Manipulation in Checkout API— hackadvisor
- [web][free]Chocolate Drop— alfactf
- [web][Pro]Flag Shop— hackerlab
- [web][Pro]Lab 216 — ShelfWave — IDOR Price Manipulation in Checkout— hackadvisor
- [web][Pro]Lab 22 — GrubFleet — IDOR in GraphQL Store Management API— hackadvisor