Business logic vulnerabilities when wrong password entered successful on the third attempt?
|
I’ve been reading about Business logic vulnerabilities and can’t help but wondering how’s the flaw in the following image possible? Why does the 3rd attempt successful even when the wrong password provided? Or do I interpreted it wrongly? Can someone help to explain? Or provide simple code for this flaw? submitted by /u/w0lfcat |
