Dark C0d3rs
HackerOne Disclosed Reports - 2026-02-09 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2026-02-09 (/Thread-HackerOne-Disclosed-Reports-2026-02-09)



HackerOne disclosed reports - 2026-02-09 - hashXploiter - 02-10-2026

Logo
Low
resolved

Unlimited Reuse of Coupon Code Allows Free Shipping on All Orders on ██████████


Bug reported by Aneeeketh was disclosed at February 9, 2026, 3:57 pm   |   Business Logic Errors

A vulnerability was found in the coupon code system of the ██████████ online store. The coupon code for free shipping could be used multiple times on any number of orders without any restrictions or tracking. This allowed users to bypass shipping charges indefinitely, resulting in a direct financial impact on the company's revenue. The vulnerability was caused by the lack of server-side validation to limit the usage of the coupon code.