View Issue Details

IDProjectCategoryView StatusLast Update
0006698OXID eShop (all versions)4.04. Securitypublic2019-10-29 11:24
Reportercesnauskast Assigned To 
Status resolvedResolutionfixed 
Target Version6.1.5Fixed in Version6.0.6 
Summary0006698: It's possible to search for e-mail addresses via gift registry search
DescriptionIt's possible to find out e-mail addresses from gift registry search panel
Steps To ReproducePre-conditions:
1. There exist a registered user (i.e. [email protected]) with at least 1 item added to gift registry
2. Under My account->My gift registry an option "Everyone shall be able to search and display my gift registry" is set to "Yes"

1. Open shop (i.e. demoshop)
2. Go to "Public gift registries" (at the bottom of the page, under "Services")
3. Enter part of the possible e-mail address (i.e. or just "@")

In the search results you will see something like "Gift registry of John Doe"
By knowing this information you can guess the username of the email (i.e. [email protected], [email protected], [email protected], etc.)

TagsData Privacy, Email, Gift Registry
ThemeNot defined
BrowserNot defined
PHP VersionNot defined
Database VersionNot defined


There are no notes attached to this issue.