davidhedlund / Feedback-for-websites

0 stars 0 forks source link

aliexpress.com: Duplicated security questions not detected from the client-side #26

Open davidhedlund opened 6 years ago

davidhedlund commented 6 years ago

Step 1

Click on Set Security Question

screenshot from 2018-03-26 04 26 45

Step 2

screenshot from 2018-03-26 04 28 07

Click on the By Email Verification button, check your mail, and enter the code.

Screenshot at 2021-06-12 01-27-08

Screenshot at 2021-06-12 01-27-31

In order to detect duplicated questions you have to click on the Submit button first as seen below. This could be detected on the client-side with a script.

Screenshot at 2021-06-12 01-40-20