VendXv1.0
READY

Target Configuration

Exploit Pipeline

1
🔍 Discover Products
2
💳 Poll Payment Status
3
📦 Create Order
4
Force Success
5
Verify Order
6
🎰 Trigger Dispense
exploit-terminal

$ waiting for exploit launch...

# Vulnerability: Server accepts client-supplied

# order_status with no payment verification

$ Configure target and click "Launch Exploit"

⚠ Vulnerability Details

Type: Broken Access Control — Client-Side Enforcement
Endpoint: PUT /orders/{id}
Flaw: Server trusts client-supplied order_status without verifying payment completion
Impact: Full product dispensing without payment — complete business logic bypass