Supporter
Supporter
Offline
0
Hello,

Simply by changing the id in the provided link in email, or in the link in "My Payments - -View details" users can access any valid id.
This should be stricly forbidden if the invoice-payment is not linked to the logged in user !

?option=com_invoices&view=payment&id=#

Why is that? Can we do something to this "vulnerability" ?
Responses (1)
  • Accepted Answer

    Supporter
    Supporter
    Offline
    Thursday, June 27 2019, 09:08 AM - #Permalink
    0
    UP
    this is an important issue that needs to be fixed ...
    The reply is currently minimized Show
Your Reply