Ecommerce Security Checklist: Sweepstakes, Coupon 2023

Main Contents
  1. Sweepstakes/Promotion
  2. Voucher/Coupon

- random draw
- Stolen prizes/points
- Tampering with lottery points/times
- concurrent lottery
- Invitation code XSS (Verification code URL may contain user name, the user name can be changed to XSS code)


- Swipe vouchers/coupons in batches
- Change voucher amount/quantity
- Change Coupon Quantity
- Concurrency logic loopholes (burp obtains coupons in batches, etc.)

Parts of E-Commerce System Security Checklist
