Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Bypassing access controls using email address parsing discrepancies (Apprentice) · 🇬🇧
- PortSwigger — Excessive trust in client-side controls (Apprentice) · 🇬🇧
- PortSwigger — Flawed enforcement of business rules (Apprentice) · 🇬🇧
- PortSwigger — High-level logic vulnerability (Apprentice) · 🇬🇧
- PortSwigger — Inconsistent security controls (Apprentice) · 🇬🇧
- PortSwigger — Authentication bypass via encryption oracle (Practitioner) · 🇬🇧
Curated resources
PortSwigger labs practicing Business Logic Vulnerabilities (12)
← Back to the full glossary Last updated: 2026-08-17