Business logic vulnerabilities when wrong password entered successful on the third attempt?

Business logic vulnerabilities when wrong password entered successful on the third attempt?

I’ve been reading about Business logic vulnerabilities and can’t help but wondering how’s the flaw in the following image possible?

Why does the 3rd attempt successful even when the wrong password provided? Or do I interpreted it wrongly? Can someone help to explain? Or provide simple code for this flaw?

https://portswigger.net/web-security/logic-flaws

https://preview.redd.it/es5blr3uzjaa1.png?width=837&format=png&auto=webp&s=55e8abf2e594162bea21f3593b2ac82d7d7f6322

submitted by /u/w0lfcat
[link] [comments]

Read More >>

Picture Of The Day

Soldiers from Carpathian Sich international battalion near the front near Kreminna, Ukraine, January 3. REUTERS/Clodagh Kilcoyne  WNU editor: The above picture is from this photo-gallery …. Inside the battle for Ukraine: Scenes from the frontli…

Read More >>