Hi,
whilst making some modifications to the reciept page I noticed that the order shown is controlled by the open query string.
Checkout/Receipt.aspx?OrderNumber=18&OrderId=118
by simply changing this to;
Checkout/Receipt.aspx?OrderNumber=17&OrderId=117
I was able to see an order for a different user. I am sure this has been addressed, can you please let me know what to do to remove this issue.
Cheers,
Rob.
Security issue?
Re: Security issue?
I am unable to reproduce it on 7.0.3. What is your application version?
- jmestep
- AbleCommerce Angel
- Posts: 8164
- Joined: Sun Feb 29, 2004 8:04 pm
- Location: Dayton, OH
- Contact:
Re: Security issue?
I was unable to reproduce on 7.0.2. Have you changed the web.config file in the members folder where it denies all users except on the wishlist?
Judy Estep
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx
- igavemybest
- Captain (CAPT)
- Posts: 388
- Joined: Sun Apr 06, 2008 5:47 pm
Re: Security issue?
Can you do this just when logged is as an admin? You said you were modifying something. Try it not logged in as an admin.