No Rate-limit on Promo
Steps To Reproduce:
Go to URL -
https://abc.target.com/product/121/checkout/promo
Navigate to
Offer/Promo/Coupon code
option
Enter the random digit
Intercept the Request
and Send to intruder
Apply payload &
Start attack
Impact :
Financial Loss, an attacker can easily bruteforce all promo/coupon/Offer codes.
Last updated