Serious security issue

    May 2009

    Serious security issue


    I was notified by a customer who registered on out website today. They created an account only to see another persons address in their account.

    I myself created a test account and the same thing happened. I have gone through the SQL tables and cannot see how this can be linked. Has this ever been reported before and how can we fix this. It's a serious error.

    I've spoken to all who have access to StoreFront and nobody has changed anything that could possibly cause this. Does anyone know what possible SQL tables this has affected?

    So far I've looked at


    All the details look correct in that the test account I created looks fine but it's linking to another persons file.


    Oct 2009


    Please submit a ticket to support for this issue. It is quite possible that there was a record created for customer record 0 which is getting transferred to full customer record when the customer registered. Though we will need to take a look. This is not behavior we normally see.