Jump to content

Checkout price 0 for products


xpindia

Recommended Posts

On 10/3/2018 at 9:48 AM, xpindia said:

Now its working fine, but one customer purchased products worth 40,000 rs and paid only 200 rs. Which is kinda scary for the store owner, how could the software allow a checkout with 0 price.?

Apple just had 500 phones bought for 1 buck due to the same validation error that the pen tester reported already and they didnt seem to care:) The cart module does not do a database pull for is product a price in my cart really what product a price is in the product module. It is fed whatever is passed in via URL > scary huh... These url hacks are pretty well known to the pen testers and as more online training becomes available the Crackers will have the knowledge at a very early age:)

 

Edited by jstillings1 (see edit history)
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...