View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0005091 | OXID eShop (all versions) | 4.04. Security | public | 2013-04-30 11:44 | 2014-07-29 13:06 |
Reporter | fcos | Assigned To | |||
Priority | high | Severity | minor | Reproducibility | always |
Status | resolved | Resolution | fixed | ||
Product Version | 4.6.5 revision 49955 | ||||
Target Version | 4.7.14 / 5.0.14 | Fixed in Version | 4.9.0_5.2.0_beta1 | ||
Summary | 0005091: Newsletter force_sid=x | ||||
Description | If you subscribe for an newsletter with no active session, the doubleoptin mail has force_sid=x, this cause some critical problem like changed user baskets... seems like it should be fixed in https://bugs.oxid-esales.com/view.php?id=1610 but i can reproduce always has anyone an hotfix for this? | ||||
Tags | No tags attached. | ||||
Theme | All | ||||
Browser | All | ||||
PHP Version | any | ||||
Database Version | any | ||||
related to | 0001610 | resolved | alfonsas_cirtautas | URL params with "sid" in name are interpreted as session ID and replaced with "sid=x" automatically |