Past payments using the Direct Debit method keep subscriptions active even if payments fail
None
N
Nord Security
Submitted None
Actions:
Reported by
zaitunoil
Vulnerability Details
Technical details and impact analysis
I think this is a vulnerability that has no impact but it violates
I found many accounts that are actively subscribed even though the payment failed, this is because the payment uses the Direct Debit method, and you have deleted it.
Because Direct Debit payments have been deleted and no longer work or can be used or cannot be detected by the system, maybe because of this the system considers payments to be legitimate and gets a subscription.
Maybe you can deactivate all subscriptions for accounts that don't have successful payments.
I know this is not a vulnerability that I report, but this is an invasion of your site's privacy.
thanks.
## Impact
Payment failed but get a subscription.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Business Logic Errors