00:01
In this question, let us have a look at how an attacker might exploit the scenario.
00:08
So the first thing would be changing the widget type.
00:18
So what this can do is, an attacker can modify the url parameters and this can lead to the type of change in the url.
00:38
So for example, they might change the widget type from a low cost product to a high cost product.
00:44
So this will result in the potential financial loss for the company.
00:50
Then we are looking at altering the unit price.
00:58
So this tells us that by manipulating the unit price parameter in the url, we, that is an attacker could potentially set an extremely low price for a very high value product.
01:14
So again, we can say that this could lead to the significant financial losses.
01:24
So which is also again bad for the company.
01:29
Then we go for the modifying quantity.
01:38
So here an attacker could manipulate the quantity parameter to order an excessive number of items.
01:46
So it is done, that is the manipulation of quantity parameters is done...