Reset the password of any account in China Mobile 12580 Mall (batch modification allowed)
Reset the password of any account in China Mobile 12580 Mall (batch modification allowed)
Can be modified without any verification
The original password is to be verified, and the reset link is obtained through the mailbox
Later, during the resetting process, it was found that the previous process was redundant and direct access was fine.
Http://12580.10086.cn/new/member/loginReg_addPassword.do? Memberno = 309966993 & type = findPassword & sitepassword = catr1234
The original request is post and changed to get request.
Originally, there was a random and sitepassword2 parameter, and later it was found completely redundant.
I tested it with my own account. I didn't perform batch tests. I didn't report any errors when I modified my password multiple times. It means I can perform batch tests and I am very kind.
Solution:
Add Verification