security problem
-
Hello
Today I find a big problem: invoice are visible for everyone. a customer or a visitor tap URL of invoice like https://www.mywebsite.com/wp-content/uploads/ywpi-pdf-invoice/Invoice/2017/09/Invoice_512.pdf&usg=OFLRFoeofroOFFVn-KIeifKLroMj_-_
ok but if there is no usg or a different usg, like: https://www.mywebsite.com/wp-content/uploads/ywpi-pdf-invoice/Invoice/2017/09/Invoice_512.pdf&usg= visitor is redirect to https://www.mywebsite.com/wp-content/uploads/ywpi-pdf-invoice/Invoice/2017/09/Invoice_512.pdf so every invoice can be see by everyone just by tapping the invoice number in URLHow to fix it?
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘security problem’ is closed to new replies.