Soufun has a system with loose permission control and can operate other user data in the same system.

Source: Internet
Author: User

There is no parallel permission control.

Soufangbang ERP-no parallel permission control is available for all modules of the real estate business management system. Other user modules can be operated and user accounts can be stolen.


Here are several available:

1. view other user information

2. Check internal information of other companies, internal information is not filtered across sites

After you view other user information based on the above excessive permissions, it is easy to send phishing emails.

3. Modify the property information published by other users,

"Sensitive remarks" can be used to modify the property information of other users across sites without authorization. The next time a user enters the modification, the user will go across sites.


4. Injection exists in multiple places, but filtering protection is implemented,


Http:// Newsid = 4

Http:// Deptid = ********* & deptlevel = 1 & txtInnerUserID = 18


Verify user

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.