Jump to content

Data leak via paypal guest checkout


bugreport999

Recommended Posts

Using paypal guest checkout you can log into and view other peoples orders and account details by creating an order without login into an account as long as the email address you give paypal at guest checkout matches an email address on the online store.

I have taken some screenshots of what you can access after using paypal guess checkout without login into your store software after creating an order (have blurred personal information) .

Opera Snapshot_2020-07-30_220853_www.anime-on-line.com.png

000036.pdf.png

Opera Snapshot_2020-07-30_220949_www.anime-on-line.com.png

Link to comment
Share on other sites

Quote

long as the email address you give paypal at guest checkout matches an email address on the online store

As per our understanding, You are saying if my email id is [email protected] & placing order using the using the PayPal then PayPal will the details of the [email protected] but One thing is not clear i.e. How other customer will have access to my PayPal account i.e. [email protected] (As login into PayPal account is also required with the same email id)?

Kindly confirm if our understanding are correct regarding the issue?

Edited by Knowband Plugins
Update (see edit history)
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...