The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

I don't understand business logic vulnerabilities image example in the web

wof | Last updated: Sep 30, 2024 01:58PM UTC

In the portswigger web-security section: https://portswigger.net/web-security/logic-flaws The following image is used to describe the business logic vulnerabilities https://portswigger.net/web-security/images/logic-flaws.jpg I understand that the first two attempts failed due to wrong password. What I don't understand is how the third attempt caused the combination of username and password to be correct?

Ben, PortSwigger Agent | Last updated: Oct 01, 2024 08:26AM UTC