Problem site http:// SC .m.sohu.com No 1 parallel permission modify arbitrary user shipping address register 2 accounts A Account UID = 0c0525ac6b934bas B account UID = 672f91694a6a485s A account access http:// SC .m.sohu.com/uc/v2/profile/modifyUserAddress modify hidden Domain value for B UID submit check that the harvest address of Account B is successfully modified. The information of account A has not been modified! No 2 Storage xss access http:// SC .m.sohu.com/uc/v2/product/list page below there is the latest redeem casually click a user http:// SC .m.sohu.com/uc/v2/user/otherByUid? Uid = fb3edcfcc1c446as (the link here can know other people's UID. If he saw a good exchange, he was decisive to change his shipping address) then see the sending information http:// SC .m.sohu.com/uc/v2/message/friendDialog? OtherUid = fb3edcfcc1c446as sends a message cookie is httponly. Do not go deep in No 3 mailbox leak a user http:// SC .m.sohu.com/uc/v2/message/friendDialog? OtherUid = fb3edcfcc1c446as view source code
Solution:
You are more professional!