vulns.co
/
GKData.io MCP

Back to Reports

A negative quantity changed the amount charged

The price that counts is the one the server stores. One owned order is enough. This card does not include the order body.

Editorial decision card. This page links to a source-verified public disclosure and contains only original defensive analysis. It does not mirror upstream HTML, payloads, attachments, private submissions, or exploit steps.
Original severity
Critical (9 ~ 10) source-reported; not rescored by vulns.co
Public source
hackerone disclosure
Program / vendor
Upserve
Product / surface
Online order total
Weakness
Business logic errors
Affected boundary
The price the client sent and the amount the server charged
Disclosure date
2019-07-06
Public status checked
2026-09-28
Public attribution
fuzz

What the evidence established

Upserve's summary says an order total could be changed by including an item with a negative quantity, and the lower total was what the system charged. The weakness label is business logic errors. The disclosed severity is a critical range.

Why the impact was credible

The source reported that the charged amount no longer matched the items a customer would be expected to pay for.

Durable engineering lesson

The price that counts is the one the server stores. One owned order is enough. This card does not include the order body.

Control pattern

Reject a quantity the menu does not sell, and recompute the total on the server from stored prices.

Primary public disclosure

Read the original source ↗

Upstream availability and wording can change. Public status was last checked 2026-09-28.