logo

How a Business Logic Vulnerability Led to Unlimited Discount Redemption

ID: 53171822-db90-5da9-921d-80d2034c63d0

STIX ID: report--53171822-db90-5da9-921d-80d2034c63d0

Feed Name: HackerOne Blog

Threat Score
45/100

Date Published: 2024-11-27

Date Updated: 2026-06-12

...
...

This document explains what business logic vulnerabilities are, their potential business impacts (financial loss, data breaches, reputational harm, etc.), industry prevalence, and mitigation approaches, and it presents a case study where a race condition in Stripe allowed repeated redemption of a $20,000 discount resulting in large potential fee-free transactions before being fixed and rewarded with a bounty.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.