IDOR vulnerability (Price manipulation)
Program: Acronis
Bug Type: IDOR
Bounty: Unspecified
Date: 2021-11-17
IDOR
Summary
The researcher found a IDOR vulnerability in payment processing that will lead to price manipulation i.e the increase and decrease of price in a marketplace. To reproduce the bug, go to the the website (acronis.cz), buy any product go to cart and click on buy now, intercept the request and change the price and forward the request.