Problem with Carts between users

  • Posts: 634
  • Thank you received: 16
8 years 5 days ago #255861

-- HikaShop version -- : 2.6.4
-- Joomla version -- : 3.6.4
-- PHP version -- : 5.6.25
-- Browser(s) name and version -- : Any

I have this situation:

User 1 is logged in Chrome with a cart with 5 products.

User 2 is logged in Safari with no cart.

In the two browsers I have cleared all browser caches, cookies, etc.

Now:

1. I access the cart through the user control panel.

I get the cart both in the content area and in a cart module.

Then I copy the URL of this browser session.

2. I paste the User 1 URL in Safari where user 2 is logged.

3. In Safari I see a message informing I can't view the information,

But in the Hikashop Cart Module now I can see the cart items of User 1.

Then, if I press checkout the content area also adquires the cart items of User 1.

And I can proceed to pay them.

–––––
This makes me thing anyone guessing cart URLS with try and retry ids can view carts from anonyomus clients.

Am I wrong?

Is there something I forgot to setup?
–––––


-- Víctor

Please Log in or Create an account to join the conversation.

  • Posts: 82868
  • Thank you received: 13378
  • MODERATOR
8 years 4 days ago #255925

Hi,

Thanks for your feedback. You're totally right, that shouldn't be possible.
I've been able to reproduce the problem and added several fixes on our end to avoid that.
You can download the install package on our end and install it on yours to get those fixes.

The following user(s) said Thank You: PeterChain, PolishedGeek

Please Log in or Create an account to join the conversation.

Time to create page: 0.071 seconds
Powered by Kunena Forum