VirtueMart Forum

VirtueMart 2 + 3 + 4 => Virtuemart Development and bug reports => Topic started by: antonino78 on October 31, 2012, 16:14:26 PM

Title: serious problem Order Detail
Post by: antonino78 on October 31, 2012, 16:14:26 PM
I noticed that the page of the order form can show anyone.
Just enter the url in the browser receives the customer with the order.
example: view your order online
This seems to me a very serious thing because I can see all the customer data! >:(
Title: Re: serious problem Order Detail
Post by: AH on October 31, 2012, 22:06:22 PM
Could you explain in more detail please including version of VM
Title: Re: serious problem Order Detail
Post by: jenkinhill on November 01, 2012, 18:16:51 PM
And are you still logged in as superadmin when you do that?
Title: Re: serious problem Order Detail
Post by: antonino78 on November 02, 2012, 11:05:01 AM
the page that opens is the (order detail) site administrator.
I did a test with another computer and the page is always open!
The url that problem is this: http://www.mysite/index.php?option=com_virtuemart&view=orders&layout=details&order_number=00b000&order_pass=p_0c5fa

joomla 2.5 - virtuemart 2.0.12f
Title: Re: serious problem Order Detail
Post by: bytelord on November 02, 2012, 11:35:05 AM
hmm,

yes .. because your url you send have the order number and order password in the url ... this is used when a client checkout as a guest (or not) to review his order ... so ... check your url
Title: Re: serious problem Order Detail
Post by: antonino78 on November 02, 2012, 11:42:05 AM
Quote from: bytelord on November 02, 2012, 11:35:05 AM
hmm,

yes .. because your url you send have the order number and order password in the url ... this is used when a client checkout as a guest (or not) to review his order ... so ... check your url

But there is a risk that this url can be displayed on the web?
This can cause problems with customers because their data can be viewed by anyone
Title: Re: serious problem Order Detail
Post by: bytelord on November 02, 2012, 11:47:11 AM
and how can be viewed by anyone? That url is send it to the customer mail address when he orders ...
Please explain exactly the issue ... where did you find that url? from the email you received after the order? yes this is complete normally and secure ... each order have different number and password that is been created using numbers and letters ...