Discussions
URGENT SECURITY BUG: Knowledgebase Displays Confidential Info
I submitted this support case in October and again in December (case #638147) with no response from NS. Can anyone here help me out? This is a huge problem for us because most of our customers access our Knowledgebase and have the ability to navigate to confidential information.
Please provide detailed steps to reproduce the problem:
1. Publish Knowledgebase to Customer Center
2. NO inventory items are available "online"
3. NO inventory items have any store description fields (or any store fields for that matter) filled in
4. Log into Customer Center, perform a Search (left-hand search box) for keyword such as "license"
Result:
All inventory items containing the keyword appear in search results - including pricing and full descriptions of everything we sell. This is a huge problem since we do not have a published price list.