Context#
The client displays a total; the server stores line items in session or a draft order. If the capture step trusts client-submitted amounts or stale session totals, the paid amount can diverge from catalog prices.
Theory#
Compare every fee and tax field against authoritative catalog and jurisdiction rules on the server at capture time, not only at cart creation.
Practice#
- Change quantity or unit price in a hidden field between review and pay in a staging checkout; diff the charged amount in payment provider logs.
Tools#
- Burp Suite