No Rate-limit on Promo
Steps To Reproduce:
Go to URL -
https://abc.target.com/product/121/checkout/promo
Navigate to
Offer/Promo/Coupon codeoption
Enter the random digit
Intercept the Requestand Send to intruder
Apply payload &
Start attack
Impact :
Financial Loss, an attacker can easily bruteforce all promo/coupon/Offer codes.
Last updated