Weaver eteams_oa system unauthorized modification of arbitrary user information
Entering https://www.eteams.cn/login/demo
Then log on to a common user:
Click the person at the beginning of the page:
Capture the package to get a link:
Https://www.eteams.cn/profile/summary/8005824116863355409.json? _ = 1408094249509
At this time, we remember 8005824116863355409.
Here we modify the user information:
Modify the phone number, capture the package, and replace the employee. id in the package with 8005824116863355409 as follows:
Url: https://www.eteams.cn/base/employee/saveProperty.json
Postdata:
Employee. id = 8005824116863355409 & propertyName = telephone & employee. telephone = test
After sending the message, go to the message page to check whether the personal information has been changed:
OK. In fact, you can not only change the phone number but also change the recipient's email.
Solution:
Filter