Print Page | Close Window

Possible bug with the recent XSS patch.

Printed From: ProductCart E-Commerce Solutions
Category: ProductCart
Forum Name: Using ProductCart
Forum Description: Running your store with ProductCart
URL: https://forum.productcart.com/forum_posts.asp?TID=4546
Printed Date: 05-March-2025 at 11:01pm
Software Version: Web Wiz Forums 12.04 - http://www.webwizforums.com


Topic: Possible bug with the recent XSS patch.
Posted By: Brett
Subject: Possible bug with the recent XSS patch.
Date Posted: 14-June-2011 at 10:25pm
I believe the patch included one file which was something like view message for the pcadmin folder. I tried to consolidate a customer account and the message came up like this:

Quote
The email you have chosen is already in use by another customer. If you still wish to use this e-mail for this customer account, <a href=''viewcustb.asp?key4=customeremail@address.com''>search</a> for all customers with the same e-mail address, consolidate their accounts into one using the corresponding feature (orders are moved to the consolidated account), and then remove the accounts that are no longer needed.


So the URL isn't correctly appearing. Is anyone else experiencing this error?



Replies:
Posted By: ProductCart
Date Posted: 15-June-2011 at 2:27pm
Hi Brett: we are looking into this. The security fix we introduced is causing the issue. We are reviewing the matter and we'll have a solution soon.

-------------
The ProductCart Team

Home of ProductCart http://www.productcart.com" rel="nofollow - shopping cart software


Posted By: ProductCart
Date Posted: 15-June-2011 at 6:27pm
We posted the updated patch.
../productcart/technical-support.asp#updates - http://www.earlyimpact.com/productcart/technical-support.asp#updates

Thank you for pointing out the issue with the way the fix was affecting the display of certain Control Panel messages.


-------------
The ProductCart Team

Home of ProductCart http://www.productcart.com" rel="nofollow - shopping cart software



Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.04 - http://www.webwizforums.com
Copyright ©2001-2021 Web Wiz Ltd. - https://www.webwiz.net