Race condition vulnerabilit leaves nopCommerce at risk of single-packet attacks

Outpost24 researchers today released research looking at a race condition vulnerability in nopCommerce, an open-source eCommerce platform written in C#, which aids developers in building online stores. When exploited, it allows an attacker user to redeem a gift card multiple times by using a technique called a single-packet attack. If they did this correctly, they were able to receive items for free. 

The full details can be found at this link and it is a very interesting read.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading