Race Condition allows to redeem multiple times gift cards which leads to free "money"
Program: reverb.com
Bug Type: Race condition
Bounty: Unspecified
Date: 2019-12-16
race-condition
Summary
The researcher found a Race condition vulnerability that let him redeem gift cards multiple times in an ecommerce website, the exploitation step included sending a valid gift card redeem request, quickly to exploit the race condition and therefore double the gift card expenditure.