🎯 Security Flaws on this page:
- Negative Quantity / Business Logic Flaw: Quantity inputs lack server or client minimum boundary validation. Entering negative numbers (e.g.,
-5) will reduce the total price, allowing negative balance or free items! - Client-Side Discount Code Logic: Coupon verification is written directly in client-side JavaScript. Anyone can read the source code to find coupons (like
HACKER100for 100% off) or alter the discount calculation. - Price Tampering: Cart items and their unit prices are stored in
localStorage.vuln_cartwhich any user can edit via DevTools Console (e.g.,localStorage.setItem('vuln_cart', ...)).
Your Shopping Cart
| Item | Unit Price | Quantity | Total | Action |
|---|
Order Summary
Subtotal
$0.00
Shipping
FREE
Grand Total
$0.00