mikez006
Customer
A member was able to edit the payment amount to 0.01 for any amount of credits they wanted.
I used Hide tags because I didn't want to post the method publicly.
[HIDE]Payment was received ($0.01), but the credits were not added to his account. I'm not sure why.
I asked how he did it and he said you used the "Tamper Data" plugin for Firefox.
https://www.youtube.com/watch?v=EcTTNWVYOiA
It allows him to change the price to anything he wants, which is how he was able to make a $.01 payment even though the minim is set to $2.50.
Even though the credits weren't added to his account, I'm afraid with a little more work someone would be able to figure it out. He only tried once.
[/HIDE]
Can you please add a fix for this flaw so price can't be changed?
I used Hide tags because I didn't want to post the method publicly.
[HIDE]Payment was received ($0.01), but the credits were not added to his account. I'm not sure why.
I asked how he did it and he said you used the "Tamper Data" plugin for Firefox.
https://www.youtube.com/watch?v=EcTTNWVYOiA
It allows him to change the price to anything he wants, which is how he was able to make a $.01 payment even though the minim is set to $2.50.
Even though the credits weren't added to his account, I'm afraid with a little more work someone would be able to figure it out. He only tried once.
[/HIDE]
Can you please add a fix for this flaw so price can't be changed?