Business logic abuse

Business logic abuse uses the application exactly as built, in a sequence or at a scale nobody intended.

Ordering a negative quantity. Applying the discount twice. Cancelling after despatch. Running a legitimate action ten thousand times. No security control is bypassed because none applies, and scanners cannot find it because nothing is technically wrong. It is found by people who understand the business.

Checked against the primary source.

More on Application security