Important - Security Issue FixedPublished: Sun, 25 Jan 2009
This security issue only effected those clients who are using 1shoppingcart.com, but as the system grows, other potential security exposures could have cropped up.
The security risk was located in the log in page to the admin panel, which contained links at the top of the page to other portions of the admin section. The links also contained an automated log in to 1shoppingcart.com which was not protected by our log-in security process since it was an external link.
We have therefore removed all links at the top of the login page, except the "Launch Main Site in new weindow" link, to make certain that any security issues can not be exposed.
Fortunately there were no hacks, and nobody was compromised, since we closed the potential problem BEFORE it was discovered.
|