Hey Orenria, thanks for pointing this out to us! We'll be in contact via email communication to get some more information on whats going on so we can get this sorted.
This bug has now been fixed. All "auto-login urls" that were created before the fix have been disabled. Anyone that was potentially affected will be prompted to login again on their next visit. This is to make sure we logout anyone that is not logged into their own account.
We'll be doing some research to see who all was affected and what the effects might have been. We don't store credit card data, so there's no issue there. We do store member email addresses, so it's possible that those were exposed.
Comments
You can go into their account settings too.
Hey Orenria, thanks for pointing this out to us! We'll be in contact via email communication to get some more information on whats going on so we can get this sorted.
Obsidian Portal Dungeon Manager || [email protected]
Thanks for pointing this out!
This bug has now been fixed. All "auto-login urls" that were created before the fix have been disabled. Anyone that was potentially affected will be prompted to login again on their next visit. This is to make sure we logout anyone that is not logged into their own account.
We'll be doing some research to see who all was affected and what the effects might have been. We don't store credit card data, so there's no issue there. We do store member email addresses, so it's possible that those were exposed.
Obsidian Portal Developer
After analysis, it doesn't appear that anything obviously malicious was done while the bug was in place.
We can't tell if email addresses were viewed or not, so it is possible that email addresses were exposed.
If you notice anything missing or odd, email support and we will look into it.
Obsidian Portal Developer
Thanks for checking!
"I met a traveller from an antique land....."
CotM May 2016: Mysteria: set in Wolfgang Baur’s MIDGARD.
Previous CotM Aug 2012: Shimring: High Level Multiplanar Campaign
Inner Council Member
Awesome catch!!!
Just trying to help out.