User able to bypass add-on restrictions in web forms - when multiple types of add-ons are available

A web user may be able to bypass membership add-on restrictions if multiple add-on types are available.

For example: if there are 2 add-on types and both are set to only allow 1 per member, a web user may still be able to add 2 of the same type to the cart.
This issue has been resolved. If you experience this error, please chat with support to provide the exact steps that were taken.
 

Steps to Duplicate

Preconditions:
- Membership program exists with multiple levels and is approved for web
- 2 types of "additional member" add-ons are active on the membership
- For both the add-ons, "Can purchase multiple" is set to NO
- Add-ons are also available for web (Web > Manage Membership Forms > Form Options)
 
  1. Go to Web > Manage Membership Forms
  2. Open the URL for the program in the precondition
  3. Select a level. 2 add-on buttons appear; 1 for each add-on type
  4. Click the button for Add-on Type 1
  5. Enter additional member information. Note Add-on Type 1 button is not removed. Both add-on buttons are still present
  6. Click the Add-on Type 1 button again
  7. Enter additional member information
  8. Add to cart
  9. Fill out all required fields and proceed to payment
  10. Enter payment info and complete order

Environment

 Altru Arts & Cultural
 Yes
 4.91
 4.94

Was this article helpful?