🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenSecurity Weekly - A CRA Resource: What AI Researchers See Beyond AI(01.09.2026 um 15:00 Uhr)
🕵️ SicherheitslückenSecurity Weekly - A CRA Resource: AI Security Findings Aren’t Proof(02.09.2026 um 19:00 Uhr)
🕵️ SicherheitslückenSecurity Weekly - A CRA Resource: Linux Threat Hunting - PSW #942(03.09.2026 um 23:14 Uhr)
🕵️ SicherheitslückenMy Life, AI and the Future of LiveOverflow(23.08.2026 um 19:53 Uhr)
⚠️ Malware / Trojaner / VirenPC Security Channel: How North Korean Hackers end up in your Network(24.08.2026 um 20:30 Uhr)
⚠️ Malware / Trojaner / VirenPC Security Channel: Undetected Steam Malware: Sent by Viewer(28.08.2026 um 21:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenSecurity Weekly - A CRA Resource: What AI Researchers See Beyond AI(01.09.2026 um 15:00 Uhr)
🕵️ SicherheitslückenSecurity Weekly - A CRA Resource: AI Security Findings Aren’t Proof(02.09.2026 um 19:00 Uhr)
🕵️ SicherheitslückenSecurity Weekly - A CRA Resource: Linux Threat Hunting - PSW #942(03.09.2026 um 23:14 Uhr)
🕵️ SicherheitslückenMy Life, AI and the Future of LiveOverflow(23.08.2026 um 19:53 Uhr)
⚠️ Malware / Trojaner / VirenPC Security Channel: How North Korean Hackers end up in your Network(24.08.2026 um 20:30 Uhr)
⚠️ Malware / Trojaner / VirenPC Security Channel: Undetected Steam Malware: Sent by Viewer(28.08.2026 um 21:00 Uhr)

26 🕛 kürzlich 4 Min Lesezeit CVE-RADAR
0

Client-Side Price Manipulation: Pay Whatever You Want at Checkout

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

Exploiting a server-side validation failure in 's checkout sends the order total straight from the browser. The server saves whatever it receives without recalculating from actual product prices. Change it to a penny, the order goes through at a penny.






Table of contents






Lab setup



From an empty directory:




CODE
npx create-oss-store oss-store
cd oss-store
npm start





Or with Docker (no Node.js required):



CODE
docker run -p 3000:3000 leogra/oss-oopssec-store





The app runs at http://localhost:3000.





Vulnerability overview



When you buy something on



Click "Complete Payment" and the browser fires off a POST with the order details, including the total the frontend calculated.





Exploitation





Configuring the proxy



Set up Burp Suite as an intercepting proxy (browser traffic through 127.0.0.1:8080). Leave interception off for now.





Preparing the order



Add products to your cart. Higher-priced items make the result more obvious. Go through checkout until you hit the payment page.







Looking at the request



The request body is JSON with the order details:







Completing the attack



Forward the modified request and turn off interception. The server processes the order at your price.





Capturing the flag



The order confirmation shows the purchase at the modified total. The server notices the mismatch and returns the flag:



CODE
OSS{cl13nt_s1d3_pr1c3_m4n1pul4t10n}





/ ·
·










   ____  ____ ____     ____                  ____            ____  _
/ __ \/ __// __/ / __ \ ___ ___ ___ / __/ ___ ____ / __/ / /_ ___ ____ ___
/ /_/ /\ \ _\ \ / /_/ // _ \ / _ \(_-<_\ \ / -_)/ __/_\ \ / __// _ \ / __// -_)
\____/___//___/ \____/ \___// .__/___/___/ \__/ \__//___/ \__/ \___//_/ \__/
/_/

# Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start

# Docker
docker run -p 3000:3000 leogra/oss-oopssec-store

# Then open http://localhost:3000 and start hacking

















  • Disclaimers



    Do not deploy OopsSec Store on a production server. This application is intentionally vulnerable and should only be used in isolated, local environments for educational purposes.



    Do not exploit vulnerabilities on systems you don’t have explicit authorization to test. Unauthorized access to computer systems is illegal. Always obtain proper permission before performing security testing.






    Feedback & Support



    Having trouble following this writeup? Found a typo or have suggestions for improvement?



    Feel free to open an issue or start a discussion on GitHub.

    Vollständiger Original-Bericht
    Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
    ↗ Original-Artikel auf dev.to lesen
    Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    Teilen mit Netzwerk & Team:

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 51%
    🟡 In Evaluierung 27%
    🟢 Keine Auswirkung 15%
    Spannende Innovation 7%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    1 Quelle
    Fixing Software Weaknesses Rather Than Just Finding More Flaws - ASW #398
    1 Quelle
    What AI Researchers See Beyond AI
    1 Quelle
    The CAPTCHA Is Actually the Attack
    Ähnliche Beiträge
    🔍 Verwandte News

    Auch interessante Nachrichten Client-Side Price Manipulation: Pay Whatever You Want at Checkout

    Thematisch verwandte Begriffe: ClientSide, Price, Manipulation, Whatever · 6 Treffer

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...