Submitted earlierCofco I buy network deletes any user informationI did not verify whether the address information of any user is deleted, but I found another excuse. The same operation can be done. It's not easy to find your holes ~~~ ----------------------------- 1. delete any user address 1. Add the Receiving address and review the element. The value of this address is 4799777. Of course, this is the object to be deleted. 2. log on to user 2 and make a normal purchase. When submitting an order, an interface is provided to operate on the user's address information. During the delete operation, capture packets or httpreplay success! Return to user 1's address book bingo! 2. modify any user address 1. Add address id = 4799785 to user 1. Pay attention to the recipient's name and phone number. 2. Modify the address information at the same interface as above 3. Modify the name and phone number of the receiver. Replay 4. Results
Bingo!
Solution:
Is the score higher when the two points are unauthorized ~~~