Customer Account leakage caused by a management system design defect
If you change the bank card information of a customer's account to your own, and then settle... what will happen ........
Http://partner.funshion.com/partner Management System
No Logon Restrictions and verification identification in the test background... although the logon password is encrypted, the user name is not encrypted... you can simply bypass and crack it...
The following is the result of cracking the attack for more than 10 minutes... prove the availability of the vulnerability ..
This leaked the customer's ID Card Name, bank card phone project, etc. ...... will it be used for phone fraud or Phishing?
Just log on to a few users to prove it.
(In order not to affect normal operation, not all of them will be posted)
If you have money, you can change your bank card to your own. Can you settle for yourself?
Solution:
Filter