Jump to content

PDF Invoice Downloads


Recommended Posts

Someone alerted me to this yesterday

 

If you take the invoice download link and modify the invoice ID you can access all clients invoices

 

I cant post links yet since my account on the forum is brand new but for example yourdomain.com/clients/dl.php?type=i&id=1244

 

Where 1244 is the invoice ID. If you modify that number you can access other clients invoices without needing to be even logged in to any account at all.

 

Is there any way this can be fixed? Thanks!!

Link to comment
Share on other sites

Actually, we have noted this too when we first installed and tested 3.12 . We added a session check to a modified pdf generation tool to prevent pdfs from being viewed if no active session is available.

 

If a new clean install still does this, then you should report it as a bug, and open a ticket, as this is quite serious.

 

just my two cents...

Link to comment
Share on other sites

I can also view invoices this way. Why is that?

 

When trying to view you must change client to your whmcs directory and use an active invoice number.

 

yourdomain.com/clients/dl.php?type=i&id=1244

yourdomain.com/whmcsdirectory/dl.php?type=i&id=activeinvoicenumber

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated