What if an attacker was able to go back to the summary page, maintaining their same valid session and inject a lower cost for an item and complete the transaction, and then check out? ???Understanding the application thoroughly is a prerequisite for designing logical tests.