Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-3875

world visible credit card log a security concern

    Details

    • Type: Bug
    • Status: Done/Fixed
    • Priority: Major
    • Resolution: Fixed/Completed
    • Affects Version/s: 2.1.2
    • Fix Version/s: 2.2.0
    • Component/s: CiviEvent
    • Labels:
      None

      Description

      The paypal transaction log can be read from anybody in the internet (supposing he knows where to look)
      It discloses mail address of users registering with an event and the amount payd.

      This is a security concern

        Attachments

          Activity

            People

            • Assignee:
              amit Amiteshwar Prasad
              Reporter:
              sawjer Christian Sager
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: