Post by agira » Tue Jun 26, 2012 2:00 am

Hello,

I got very strange issue request from my customer, need to complete these steps to see it on customer's e-shop.

1. Complete registration as buyer on opencart frontpage, fullfill all required fields, address and etc;
2. Login as buyer and go on frontpage to My Account;
3. Click on My Account -> Modify your address book entries [ /index.php?route=account/address ]

It then shows summary information like this:

First Name = {***}
Last Name = {***}
Company = {***}
Address 1 = {***}
Address 2 =
City = {***}
Postcode = {***}
Zone = {***}
Zone Code = {***}
Country = {***}

Where i see NOT buyer's information but opencart owner's data!
When i press EDIT it gives to edit correct buyer's info but this summary shows wrong information.

I don't know it happen on all opencarts or just on my customer's but it pretty big leak of information as everyone who register can know e-shop owner address, name, surname and etc...

Any suggestion welcome, i think to check php files just unsure which one i need? can anyone help?

P.S. Opencart version 1.5.1.3
Last edited by agira on Fri Jun 29, 2012 1:46 am, edited 1 time in total.

CHEAP, HIGH QUALITY & FAST - From these three things possible to choose just TWO.


User avatar
Newbie

Posts

Joined
Wed Nov 30, 2011 5:27 am
Location - Lithuania, Vilnius

Post by Avvici » Thu Jun 28, 2012 6:43 am

I would recommend re-uploading all files from a fresh 1.5.1.3 install to the account folder.

User avatar
Expert Member

Posts

Joined
Tue Apr 05, 2011 12:09 pm
Location - Asheville, NC

Post by Daniel » Thu Jun 28, 2012 12:48 pm

you have done a bad backup and restore. its impossible for one customer to access another's information.

OpenCart®
Project Owner & Developer.


User avatar
Administrator

Posts

Joined
Fri Nov 03, 2006 6:57 pm

Post by agira » Thu Jun 28, 2012 6:01 pm

avvici wrote:I would recommend re-uploading all files from a fresh 1.5.1.3 install to the account folder.
To reinstall it's impossible,

1. It's running e-shop;

2. In long run this opencart installation was a lot of times modified also upgraded from some older opencart version (which installed with all previous changes another programmer) by customer's request was added many modules, including commercial theme and other modules which changed system files, it also uses vqmod but not all modules use it;

3. Many times i needed to fix something to get everything together working, sometimes was fixed opencart core or module files and etc... i spent a lot of time on every change analysis, comparison on SVN or WinMerge & etc... nothing was done without clear knowledge what every change does.

I understand then it unique and strong modified version and it saw bigger disasters which i fixed than this, just i hoped maybe someone had same issue :)

Today starting own research on this problem.

CHEAP, HIGH QUALITY & FAST - From these three things possible to choose just TWO.


User avatar
Newbie

Posts

Joined
Wed Nov 30, 2011 5:27 am
Location - Lithuania, Vilnius

Post by agira » Thu Jun 28, 2012 6:20 pm

Daniel wrote:you have done a bad backup and restore. its impossible for one customer to access another's information.
Sorry for my poor english as i see i poor explained :)

In My Account -> Modify your address book entries summary preview buyer see not another buyer information but e-shop owner's information, like e-shop owner's name, last name, address... After he press edit he see correct info, but summary shows wrong info.

BTW. It's multilingual system (6 languages) and customer said then this problem he only get when frontend language is set to same language which is default on backend.


Today i starting to research this so i will inform about situation.

CHEAP, HIGH QUALITY & FAST - From these three things possible to choose just TWO.


User avatar
Newbie

Posts

Joined
Wed Nov 30, 2011 5:27 am
Location - Lithuania, Vilnius

Post by agira » Fri Jun 29, 2012 1:44 am

Problem solved :)

That was not a bug at all. After some debugging and analysis I found then e-shop owner specified own address in backend (System->Localisation->Countries) one of countries address format field :)

Address Format:
First Name = {**}
Last Name = {**}
Company = {**}
& etc...

He wrong understood what to do here :) and entered own information :) then him info was shown in summary for every buyer from this country :)

CHEAP, HIGH QUALITY & FAST - From these three things possible to choose just TWO.


User avatar
Newbie

Posts

Joined
Wed Nov 30, 2011 5:27 am
Location - Lithuania, Vilnius
Who is online

Users browsing this forum: No registered users and 112 guests