
Challenge 9/36: Client-side Price Manipulation in OopsSec Store
ctfsecurityinput-validationclient-sideprice-manipulationweb-securityvulnerabilitychallenge
Challenge 9/36 · Trusting the Client. Client-side price manipulation. Medium difficulty · Input Validation · 30–45 min. Exploiting a server-side validation failure in OopsSec Store's checkout process to purchase products at arbitrary prices. Spin up the lab: npx create-oss-store my-ctf-lab. See it on the roadmap at https://koadt.github.io/oss-oopssec-store/roadmap#challenge-09. Walkthrough available at https://koadt.github.io/oss-oopssec-store/posts/client-side-price-manipulation (spoilers, read it once you are stuck). Star OopsSec Store on GitHub at https://github.com/kOaDT/oss-oopssec-store