Ordering Flipper

I’d like to get in touch with someone from the Flipper community in regards to a vulnerability I found which allows users to place an order for a Flipper zero even though the site says they are all sold out.

2 Likes

Cool bug. Hopefully you can share after it’s patched.

1 Like

Looks like it’s fixed now. You could go into the HTML code and change the area from being disabled to enabled which allows you to put it in your cart. It now says it can’t ship once you do that though.

1 Like

Good job letting everyone know (hopefully) before the scalpers found it.

Doesn’t look a bad bug at all. If you were to trick the site by exploiting it to buy flipper when it’s not available most likely you would end up loosing money as you wouldn’t get flipper even if you ended up paying for it with hacked site … So it wouldn’t be a very clever hack …

I suspect the order might be queued and delivered next shipment unless they manually audited the orders.