You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I was expecting that in backend (or at least in frontend) there would be a check if the order is belonging to user (or seller or admin).
It seems that anyone could access to orders of another user (thus also some additional data such as shipping address).
The text was updated successfully, but these errors were encountered:
I was expecting that in backend (or at least in frontend) there would be a check if the order is belonging to user (or seller or admin).
It seems that anyone could access to orders of another user (thus also some additional data such as shipping address).
The text was updated successfully, but these errors were encountered: