I built an intentionally vulnerable banking application for security engineers/interns, developers, & QA analysts to learn, practice secure code reviews, and test their application security knowledge in areas such as SQLi, XSS, CSRF, race conditions, API vulnerabilities, & more.
Where are the hackers/code reviewers? How many vulnerabilities can you spot in this code?
Apart from the hints, are there other places you can exploit?
Can you chain the vulnerabilities?