Major privacy bug in Orders?
Posted: Wed May 18, 2011 11:25 am
Hello,
I'm building a webshop with Products in combination with Orders.
Maybe i'm wrong but i think theres a mayer privacy bug in it.
When you're past the first page where you fill in your name and
adres. The link in your browser becomes like this:
?mact=Orders,cntnt01,confirm,0&cntnt01returnid=26&cntnt01order_id=4
When i change the last var: order_id to a lower number, i can read the name
an adres from costumers who ordered something before i did! Also
all the stuff that there buyed.
Is this true, or am i doing something wrong?
Many thanx, Job.
I'm building a webshop with Products in combination with Orders.
Maybe i'm wrong but i think theres a mayer privacy bug in it.
When you're past the first page where you fill in your name and
adres. The link in your browser becomes like this:
?mact=Orders,cntnt01,confirm,0&cntnt01returnid=26&cntnt01order_id=4
When i change the last var: order_id to a lower number, i can read the name
an adres from costumers who ordered something before i did! Also
all the stuff that there buyed.
Is this true, or am i doing something wrong?
Many thanx, Job.