### 简要描述:
RT
### 详细说明:
demo地址:http://mp.fanwe.net
老规矩注册两账号
账号A收货地址
[<img src="https://images.seebug.org/upload/201507/06180816835399c836a698d76347e4452c129167.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201507/06180816835399c836a698d76347e4452c129167.jpg)
账号B 收货地址
[<img src="https://images.seebug.org/upload/201507/06180837c023761351c45af37b9b7213d5cd96c2.jpg" alt="2.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201507/06180837c023761351c45af37b9b7213d5cd96c2.jpg)
点击账号B的提交,抓包修改地址id为账号A的地址id
[<img src="https://images.seebug.org/upload/201507/06181031f3f3908a19bb7fd9455429b5a8c86a90.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201507/06181031f3f3908a19bb7fd9455429b5a8c86a90.jpg)
查看账号A地址,发现被清除
[<img src="https://images.seebug.org/upload/201507/06181051d8fce118116d8a30c971dfad5e3cb4bb.jpg" alt="4.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201507/06181051d8fce118116d8a30c971dfad5e3cb4bb.jpg)
### 漏洞证明:
如上
暂无评论