Media Summary: Today hint: Broken Logic Today refund endpoint accept user amount refund without checking order real amount, and also Today hint: Ask support. We use XSS to get admin JWT token from localStorage Challenge link: Hint: Slugs are useful. Today vulnrability: Broken Object Level Authorization (BOLA),
Cheesy Does It Idor Bugforge - Detailed Analysis & Overview
Today hint: Broken Logic Today refund endpoint accept user amount refund without checking order real amount, and also Today hint: Ask support. We use XSS to get admin JWT token from localStorage Challenge link: Hint: Slugs are useful. Today vulnrability: Broken Object Level Authorization (BOLA),