Bug in anonymous checkout

Committee: 
Web Design
Assignee(s): 
Walt
Assignment Date: 
12/09/2008
Action Source: 
Other
Phase: 
Phase I
Expected Completion Date: 
05/04/2009
Percent Done: 
100%
Percent Done Date: 
05/04/2009
Actual Completion Date: 
05/04/2009

If one goes to checkout while not logged on, the user is presented with fields to register (or a link to logon). If one already has an account and uses that information in the registration form, then the order is placed on that account, even if the password given is wrong. This could be used maliciously. Once we are taking credit cards there will be the additional check of giving the correct credit card number which should stop most uses. If the correct password is given, the user is logged on at the completion of checkout. If the password is wrong, the user is not logged on so it is not a severe security exposure.

Required actions:

  1. report bug
  2. fix if possible
  3. wait for fix
  4. apply fix
  5. reverify
Groups: