Mike230 Posted July 13, 2007 Share Posted July 13, 2007 Someone alerted me to this yesterday If you take the invoice download link and modify the invoice ID you can access all clients invoices I cant post links yet since my account on the forum is brand new but for example yourdomain.com/clients/dl.php?type=i&id=1244 Where 1244 is the invoice ID. If you modify that number you can access other clients invoices without needing to be even logged in to any account at all. Is there any way this can be fixed? Thanks!! Link to comment Share on other sites More sharing options...
Rogue-Ident Posted July 13, 2007 Share Posted July 13, 2007 It doesn't do that for me... Actually, it gives me this message; An Error Occured. Please Try Again. Link to comment Share on other sites More sharing options...
Nathan123 Posted July 13, 2007 Share Posted July 13, 2007 I also get " An Error Occured. Please Try Again. " Maybe you should open a support ticket Mike230. Link to comment Share on other sites More sharing options...
trine Posted July 13, 2007 Share Posted July 13, 2007 Actually, we have noted this too when we first installed and tested 3.12 . We added a session check to a modified pdf generation tool to prevent pdfs from being viewed if no active session is available. If a new clean install still does this, then you should report it as a bug, and open a ticket, as this is quite serious. just my two cents... Link to comment Share on other sites More sharing options...
Joweb Posted July 13, 2007 Share Posted July 13, 2007 I can also view invoices this way. Why is that? When trying to view you must change client to your whmcs directory and use an active invoice number. yourdomain.com/clients/dl.php?type=i&id=1244 yourdomain.com/whmcsdirectory/dl.php?type=i&id=activeinvoicenumber Link to comment Share on other sites More sharing options...
trine Posted July 13, 2007 Share Posted July 13, 2007 If a mod could move this to bug reports, that would be good. Link to comment Share on other sites More sharing options...
DataHosts Posted July 13, 2007 Share Posted July 13, 2007 ***moving for verification***** Link to comment Share on other sites More sharing options...
WHMCS CEO Matt Posted July 13, 2007 WHMCS CEO Share Posted July 13, 2007 This issue is corrected in 3.2. Matt Link to comment Share on other sites More sharing options...
Recommended Posts