Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

Help! Customer info bleeding into other customer accounts!


Brainwrap

Recommended Posts

Hi, I'm relatively new to osCommerce. One of my new clients, The Scholar Program, is using version 2.2-MS2:

 

https://thescholarsprogram.com/osc/index.php?cPath=21_26

 

The problem, as he reports it, is that at least 3 customers are reporting that when they go to check out, the customer info fields are already filled out--with someone else's data! This does not appear to be an "autofill" issue with their browser; the data is for a different customer in a different state who they've never heard of. This is apparently happening even with new customers (ie, someone who doesn't already have an account--when they go to create one, some existing customers' data is already filled in!)

 

Even worse, today he reports:

 

Yesterday, we had another person call and tell us that they had someone else's info pop up on their screen.

 

Today, we had a call about this.

 

A lady placed an order with us. She received an email confirming her order as was expected. However, she also received three more emails. These emails had nothing to do with her and are concerning another lady who lives in a different state. She also received the "Order Process" sheet which I believe is only supposed to come to us. (It was the Order Process sheet though for the other lady too).

 

Obviously this is a major security issue. Any assistance or insight would be greatly appreciated. Is the entire database hosed? Is there a simple patch, plug-in or upgrade that can resolve this? Is this a known issue? (I ran a search of the forums but haven't found this issue yet).

 

Thanks in advance!

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...