Jump to content

Users see eachothers cache


Recommended Posts

I have a large security flaw in our Prestashop 1.5.4.2 installation where users can see eachothers cache. For example, on a customized product text field sometimes we see saved text/data from another user.

 

Or when checking out and it displays the addresses, it is displayed another users address which is cached.

 

So there seem to be a large security bug, where the cache is not restricted to each user id, but the cache seems to be global. Anyone recognize this issue? Anyone have ideas for solution or atleast how to narrow it down to find exactly where the problem is.

 

One thing is that this problem does not seem to happen 100% of the time. It seems to only happen sometimes and there are only few customers have have complained on seeing other users addresses and so on.

Link to comment
Share on other sites

×
×
  • Create New...