Results 1 to 4 of 4

Apparent Security Hole in Coupons/Vouchers module

This is a discussion on Apparent Security Hole in Coupons/Vouchers module within the osCmax v1.7 Discussion forums, part of the osCmax v1.7 Forums category; This is a SEVERE hole and everyone should be aware it is happening. Our store has someone that is able ...

      
  1. #1
    Lurker HVLLC's Avatar
    Join Date
    Mar 2005
    Posts
    3
    Rep Power
    0


    Default Apparent Security Hole in Coupons/Vouchers module

    This is a SEVERE hole and everyone should be aware it is happening.

    Our store has someone that is able to give themself as many $10 vouchers as he needs to reduce the amount due to below $10. Some orders he has used $40 worth of vouchers.

    This really sucks because the guy seems to know what he is doing and pays with PayPal e-check that doesn't seem to clear. If I try to refund him, it looks like Paypal will pay him out of my account regardless of whether the check clears or not!!

    Anyone know how he can send himself $10 vouchers? In looking at the administration area's gift vouchers list, I see mostly where "admin" was the issuer but there are several where his user ID was the issuee.

    This seems to be most often the following voucher that is getting used
    ---------
    Discount Coupons
    2005-03-29
    Coupon Name Coupon 10
    Coupon Name
    Coupon Name
    Coupon Description 10 percent off with this coupon.
    Coupon Description
    Coupon Description
    Coupon Amount 10.0000%
    Coupon Minimum Order 25.0000
    Free Shipping No Free Shipping
    Coupon Code 5dd5cb
    Uses per Coupon 10000
    Uses per Customer 1
    Valid Product List
    Valid Categories List
    Start Date 03/29/2005
    End Date 03/29/2006

  2. #2
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,501
    Rep Power
    567


    Default RE: Apparent Security Hole in Coupons/Vouchers module

    GV_REDEEM_EXPLOIT_FIX (GVREF)
    ---------------------------------------------
    * case: guest accounts can exploit gift voucher sent using "Mail Gift Voucher" (admin area),
    * by sharing the code until somebody logs with a valid account
    * or successfully created new account.
    *
    * obv: the session remains on user while served as a guest.
    * The gift voucher can now be reused to all guest users until
    * gift voucher is redeemed
    * soln: before releasing the gift voucher, the user must login first
    * or asked to create an account.
    *
    *
    -- Frederick Ricaforte
    Fix is here: http://www.oscommerce.com/community/...h,gift+voucher
    Michael Sasek
    osCMax Developer


    osCmax installation service - Have our professionals install osCmax on your server - same day service!
    osCmax 2.0 User Manual - the must have beginners guide to osCmax v2.0

    Stay Up To Date with everything osCMax:
    Free osCMax Newsletters - Security notices, New Releases, osCMax News
    osCMax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  3. #3
    Lurker HVLLC's Avatar
    Join Date
    Mar 2005
    Posts
    3
    Rep Power
    0


    Default RE: Apparent Security Hole in Coupons/Vouchers module

    Thanks Michael!

    It seems that fix will correct the condition where he used the admin code to send himself gift vouchers. However, I am seeing where his user account has sent vouchers also.

    I am afraid there is still a hole somewhere in the system allowing him to send himself vouchers for any amount and for free.

    Christie

  4. #4
    Member
    Join Date
    Sep 2003
    Posts
    42
    Rep Power
    0


    Default Re: RE: Apparent Security Hole in Coupons/Vouchers module

    Quote Originally Posted by msasek
    GV_REDEEM_EXPLOIT_FIX (GVREF)
    ---------------------------------------------
    * case: guest accounts can exploit gift voucher sent using "Mail Gift Voucher" (admin area),
    * by sharing the code until somebody logs with a valid account
    * or successfully created new account.
    *
    * obv: the session remains on user while served as a guest.
    * The gift voucher can now be reused to all guest users until
    * gift voucher is redeemed
    * soln: before releasing the gift voucher, the user must login first
    * or asked to create an account.
    *
    *
    -- Frederick Ricaforte
    Fix is here: http://www.oscommerce.com/community/...h,gift+voucher
    Is this fixed in OSCMAX 1.7? I don't see an upgrade patch for 1.5.5 so my first assmption would be no.

    Thanks
    Jonathan

Similar Threads

  1. Tax & Coupons Just Stopped working???
    By toddw in forum osCMax v2 Features Discussion
    Replies: 2
    Last Post: 02-16-2006, 12:16 PM
  2. 500 Internal Server Error (with no apparent reason!)
    By Willum in forum osCmax v2 Installation issues
    Replies: 5
    Last Post: 08-19-2005, 03:19 AM
  3. Discount Coupons
    By NickW in forum osCmax v1.7 Discussion
    Replies: 1
    Last Post: 03-26-2005, 11:59 AM
  4. Help With Credit Class / Coupons
    By swrecruiter in forum osCMax v1.7 General Mods Discussion
    Replies: 1
    Last Post: 02-09-2004, 12:50 AM
  5. problems with coupons
    By dreamstyles in forum osCMax v1.7 General Mods Discussion
    Replies: 0
    Last Post: 01-02-2004, 04:46 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •