There is no parallel permission control.
Soufangbang ERP-no parallel permission control is available for all modules of the real estate business management system. Other user modules can be operated and user accounts can be stolen.
Http://erp.soufun.com/Publicity/index.html
Here are several available:
1. view other user information
2. Check internal information of other companies, internal information is not filtered across sites
After you view other user information based on the above excessive permissions, it is easy to send phishing emails.
3. Modify the property information published by other users,
"Sensitive remarks" can be used to modify the property information of other users across sites without authorization. The next time a user enters the modification, the user will go across sites.
4. Injection exists in multiple places, but filtering protection is implemented,
Example:
Http://erps.soufun.com/News/NewsDetail.aspx? Newsid = 4
Http://erps.soufun.com/User/UserPurviewList.aspx? Deptid = ********* & deptlevel = 1 & txtInnerUserID = 18
Solution:
Verify user