webProeasy

Lab 193 — ShopNova — Price Manipulation in Checkout API

hackadvisor

Task: E-commerce platform where checkout API accepts client-controlled price in request body instead of validating server-side. Solution: Intercept checkout request and modify amount parameter to purchase premium membership for $0.01 instead of $9,999.99.

$ ls tags/ techniques/
business_logic_bypassclient_side_price_manipulationapi_parameter_tamperinginsecure_direct_object_reference

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups