Post by RideTheWave » Tue Sep 09, 2025 11:47 am

I have Gift Vouchers disabled (in Extensions -> Order Totals). The extension is not even installed. However, someone purchased a $1 Gift Certificate and it shows up in our orders. On our front end, there is no link to purchase vouchers. I read elsewhere to go to Settings -> Store -> edit -> Option -> Vouchers (set the voucher min to 0 and max to 0). When I set those values to 0, it gives me an error saying "Minimum voucher amount required!" and "Maximum voucher amount required!" So I've left those values at 1 for now. Does anyone know of any other way to prevent this from happening again?
Last edited by RideTheWave on Tue Sep 09, 2025 8:43 pm, edited 3 times in total.

New member

Posts

Joined
Fri May 19, 2017 8:29 am

Post by ADD Creative » Tue Sep 09, 2025 4:10 pm

Could be some sort on BIN attack. The topics below may be helpful.

viewtopic.php?t=235930
viewtopic.php?t=230326#p862363

www.add-creative.co.uk


Guru Member

Posts

Joined
Sat Jan 14, 2012 1:02 am
Location - United Kingdom

Post by OSWorX » Tue Sep 09, 2025 11:27 pm

As it seems, we should add a PR when such items are disabled those controllers should be "listen" to that and send customers to the mainpage .. and not creating anything else.
What you all think of that?

Full Stack Web Developer :: Dedicated OpenCart Development & Support DACH Region
Contact for Custom Work / Fast Support.


User avatar
Administrator
Online

Posts

Joined
Mon Jan 11, 2010 10:52 pm
Location - Austria

Post by khnaz35 » Wed Sep 10, 2025 2:16 am

I think that would be a better way than doing 404.

Got a burning question at 3 AM that even Google shrugs at? There’s a not-so-secret inbox that might just have your answer: khnaz35@gmail.com
Breathe in some nature while you're at it. It’s cheaper than therapy. :-*

Feel free to sling a bear my way via PayPal @ khnaz35@gmail.com


User avatar
Active Member

Posts

Joined
Mon Aug 27, 2018 11:30 pm
Location - Malaysia

Post by ADD Creative » Wed Sep 10, 2025 4:05 pm

OSWorX wrote:
Tue Sep 09, 2025 11:27 pm
As it seems, we should add a PR when such items are disabled those controllers should be "listen" to that and send customers to the mainpage .. and not creating anything else.
What you all think of that?
Disabling the controller would be very helpful in this case. You would also need to add options in the sittings to actually disable gift vouchers. You can disable the voucher total extension, but that doesn't stop vouchers from being purchased.

Another quick workaround is to the set the Voucher Max value to a lower value than Voucher Min in the settings. This stops gift vouchers from being purchased without having to modify the code.

www.add-creative.co.uk


Guru Member

Posts

Joined
Sat Jan 14, 2012 1:02 am
Location - United Kingdom

Post by paulfeakins » Wed Sep 10, 2025 10:57 pm

RideTheWave wrote:
Tue Sep 09, 2025 11:47 am
Does anyone know of any other way to prevent this from happening again?
Have you searched for extensions that remove the functionality?

UK OpenCart Hosting | OpenCart Audits | OpenCart Support - please email info@antropy.co.uk


User avatar
Legendary Member

Posts

Joined
Mon Aug 22, 2011 11:01 pm
Location - London Gatwick, United Kingdom
Who is online

Users browsing this forum: No registered users and 23 guests