Order notifications being sent for a deactivated staff account
Low
Vulnerability Details
Hi,
Steps to reproduce :
-
- Have a staff account with settings permission
- The staff account can go to notifications & add himself so as to get new order notifications
- Now,deactivate the staff account via the admin.
- Create a new order,you shall see that the staff still receives the order notification via email.
- This happens because the account still exists,but if staff deleted , then there is no account,hence no email) so no notification.
## Impact
- Info disclosure about a customer of a store the staff account cant have access to.
Actions
View on HackerOneReport Stats
- Report ID: 331223
- State: Closed
- Substate: resolved
- Upvotes: 16