Posting in the Magento forums has been disabled pending the implementation of a new and improved forum solution which should better serve the community.

For new questions please post at magento.stackexchange.com, the community-run support site for the Magento community. We will be providing updates on the new forum solution soon. For questions or concerns please email community@magento.com.

Magento Forum

One customer was automatically logged in as another. 
 
nick7
Jr. Member
 
Total Posts:  1
Joined:  2010-06-30
 

This morning I came to work, and our Customer service rep said that one customer in Arizona, when navigating to our homepage, was automatically logged in as a customer of ours in Texas. 

He was able to see recent orders, address’, emails, CC type, expirations, and the last 4 digits.

He actually called the customer in Texas to tell him that this happened.

Any idea how this is possible?

 
Magento Community Magento Community
Magento Community
Magento Community
 
J_T_
Moderator
 
Avatar
Total Posts:  1961
Joined:  2008-08-07
London-ish, UK
 

In terms of brand reputation management, I really wonder why you sign up with your website name to then post about a considerable problem on that very website and about customers complaining about this serious issue. But that aside…

The issue is related to session management. You don’t give ANY information about your server specs, hosting environment, session settings etc. so it’s nigh impossible to actually give good instructions on how to remedy this, but it’s usually a case of poor, shared hosting and the sessions getting mixed up. There are plenty of threads in this forum about “seeing other customer’s details”. A Google search will probably get you to the answers instantly.

 
Magento Community Magento Community
Magento Community
Magento Community
 
SimpleHelixcom
Enthusiast
 
Avatar
Total Posts:  906
Joined:  2007-08-31
Huntsville, AL
 

Hello!

In the backend, try enabling all 4 options under System > Configuration > Web > Session Validation Settings

This is especially important for load-balanced setups.

 
Magento Community Magento Community
Magento Community
Magento Community
 
Rauno
Jr. Member
 
Total Posts:  1
Joined:  2009-01-26
 
SimpleHelix.com - 12 February 2011 12:17 PM

Hello!

In the backend, try enabling all 4 options under System > Configuration > Web > Session Validation Settings

This is especially important for load-balanced setups.

Did this solution help on it?

 
Magento Community Magento Community
Magento Community
Magento Community
 
AmeshaRobber
Jr. Member
 
Total Posts:  2
Joined:  2011-11-28
 

i think you contact with your hosting services provider. thanks

 
Magento Community Magento Community
Magento Community
Magento Community
Magento Community
Magento Community
Back to top