Form the given statement i have come to know that the by changing hidden form values attacker has been able to modify the purchase price.
Step-by-step explanation:
User can change a hidden field is not different from a common field from browser or server side.
If you want to store data then user must have to store them on server -side on a session and it is a fastest way.