Potential Database Exploitation / Workaround?

While setting up my personal meeting link/calendar I stumbled across the form which prompts the scheduler to enter their first name, last name, and email. Since HubSpot does not permit duplicate email records, I quality tested the form which surprisingly did not throw an error, but rather re-wrote the first name and last name information (that is stored in our contact records) if the scheduler had entered an existing email.

This means that anyone with the calendar link (or perhaps any forms that connect to our database) have the ability to overwrite information if they enter an email that is already in use for any other properties that are displayed on the form.

Is this true? and is there any workaround for security purposes?

Thanks.

Hey, @RLehrhaupt :waving_hand: To confirm, this is working as designed. And I understand why you might want to prevent this behaviour.

Moving forward, we have two steps:

  • from my end, I’ll flag your post and comments to the product team
  • if you have a moment, please consider creating a suggestion in the Ideas forum to change this behaviour, or perhaps add in validation to the meeting form to enable/disable updating of previously completed fields. This will get your Idea both in front of the product team and allow other members to add their upvotes and feedback.

Best,

Jaycee