Media Summary: Today hint: SQL Injection. Login form is vulnerable to SQL injection with classic admin' OR '1'='1 Today hint: Broken Logic Today refund endpoint accept user amount refund without checking order real amount, and also Today hint: Ask support. We use XSS to get admin JWT token from localStorage
Bugforge Daily Challenge Cheesy Does - Detailed Analysis & Overview
Today hint: SQL Injection. Login form is vulnerable to SQL injection with classic admin' OR '1'='1 Today hint: Broken Logic Today refund endpoint accept user amount refund without checking order real amount, and also Today hint: Ask support. We use XSS to get admin JWT token from localStorage