Dashboard
AdministratorOrders0
Paid0
Pending0
SalesUS$ 0
Customers0
Items Sold0
Order Summary
Current distribution by status.
Recent Activity
| Order | Customer | Items | Amount | Payment | Status | Actions |
|---|
| Customer | Contact | Location | Orders | Total | Last Order |
|---|
| Product | SKU | Brand | Category | Price | Actions |
|---|
PIX0
Card0
Bank Slip0
PayPal0
Bitcoin0
Bank Transfer0
Reconciliation
Orders and their payment states recorded by the backend.
| Order | Method | Payment Status | Amount | Date |
|---|
Orders by status
Most represented brands in the catalog
Best-Selling Products
🔴 Academic Simulation — Broken Access Control / IDOR
This screen demonstrates the risk without performing a real exploit. In a vulnerable application, changing an identifier without validating authorization could expose another person’s order. OWASP classifies Broken Access Control as A01:2025 and recommends server-side validation, deny-by-default, and failure logging.
🟢 Protection
The panel uses an administrative endpoint protected by a session token on the backend. Orders and statuses are validated on the server. For real production: MFA, database, RBAC, HTTPS, rate limiting, and an identity provider.
Audit Log
| Date | Action | Details |
|---|
