Loading HuntDB...

Past payments using the Direct Debit method keep subscriptions active even if payments fail

None
N
Nord Security
Submitted None
Reported by zaitunoil

Vulnerability Details

Technical details and impact analysis

Business Logic Errors
I think this is a vulnerability that has no impact but it violates I found many accounts that are actively subscribed even though the payment failed, this is because the payment uses the Direct Debit method, and you have deleted it. Because Direct Debit payments have been deleted and no longer work or can be used or cannot be detected by the system, maybe because of this the system considers payments to be legitimate and gets a subscription. Maybe you can deactivate all subscriptions for accounts that don't have successful payments. I know this is not a vulnerability that I report, but this is an invasion of your site's privacy. thanks. ## Impact Payment failed but get a subscription.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors