View Issue Details

IDProjectCategoryView StatusLast Update
0000443OXID eShop (all versions)4.04. Securitypublic2008-12-15 19:46
ReporterRoman_Felger Assigned To 
PrioritynormalSeverityminorReproducibilityalways
Status resolvedResolutionwon't fix 
Summary0000443: unsecure link to review in order confirmation mail
Descriptionlink to review products contains userid.
e.g. http://demoshop.oxid-esales.com/professional-edition/index.php?shp=oxbaseshop&anid=1940&cl=review&reviewuserid=eff7e721f4d7d417218302369bfc7d64
TagsNo tags attached.
Theme
BrowserAll
PHP Version5.2.6
Database Version5.0.33

Activities

vilma_liorensaityte

2008-12-11 10:29

reporter   ~0000308

Reminder sent to: dainius.bigelis, ralf_trapp

There is a functionality, that user from order confirmation mail per link will be redirected to shop to write reviews without loggin. For this funktionality we need userid. Should we remove userid? Than user will be redirected to shop, but to write reviews he must loggin. Or should we leave it as it is?

ralf_trapp

2008-12-15 19:46

reporter   ~0000323

As it's no security issue and you have to login with your password: We leave it as it is.