Discussions
Security/Privacy issue with online custom forms
We just received a complaint from a customer that they received an order notification for an order they did not place and the Name on the order was someone they never heard of. However the email Address and billing address belonged to him. This is roughly the 5th time that a customer has complained about this exact same scenario. I spent hours looking into trying to figure it out. Netsuite says the only way it could happen is if some accessed the customers account through the customer center.
After searching the forum i found one similar case that was related to an online custom form. So i went back to the customer record and sure enough there it was a custom form submitted at the exact time the customer record changed in system notes.