Let's check the first product's stock.
We can intercept this request using the Burp Suite Proxy and forward it to the Repeater to modify it.
Proxy
Repeater
Now let's set the storeID parameter to the following and send the request:
storeID
We have solved the lab.
Last updated 2 years ago
1|whoami