Jump to content

Registration form shows data from database


ptityop

Recommended Posts

Hello,

I was running a test to check the registration roces and to my big surprise whenregistering as new customer, i have fields that are prefilled with data from existing customer that are in the database.... In the screenshot you will see that those fields were prefilled, customer exists... how comes they get there ?? looks like a serious security breach if any form can pull data up like this !! 

This actually is not the first time this happens, one day when testing to place an order, i create a new customer and I already had an adress registered which was the adress from another customer !! Is this something known. I am using latest 1.7.8.5 pesta version. Thanks for any feedback on this

 

  • Like 1
Link to comment
Share on other sites

It looks very strange, that PS automatically filled the data of saved customer. 

There is no such code exist in the PS "CheckoutAddressesStep" Controller which filled the address from different customer during the address Editing.

Can you please confirm whether you have disabled the browser autocomplete feature, as you may be conused with the browser autocomplete with PS persistence functioanlity. Kindly have a video for your reference : https://www.loom.com/share/851e3c64c2474e3ebe812f6f4a736134

Please disable the browser autocomplete , and check once agarin or share a video of the issue so that we can check and comment accordingly.

 

Link to comment
Share on other sites

It is strange indeed, but it did happen, I know had to clear cache so I cannot make a video , this is not systematic but if it hapens again I will write back, just like the adress from another customer showing up, this has not anything to do with autocomplete ... I'll monitor, thanks for your reply though.

Link to comment
Share on other sites

I forgot to upload the screenshot , i do it now, this shows the form on the registration process, the info in the fields are info from a real customer in the database, why are they showing up there .... no idea, definitelty not someone who used my computer, so not a cookie issue

regprocess.PNG

  • Like 1
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...