Just thought I would pass along a note to you all.
I was using the Bank of America WorldPoints reward redemption site (www.travelsandrewards.com/) to look for some travel arrangements. I reached a page where they advised me could not accommodate my request, and provided a "Back" button to click to return and try a different itinerary.
When the page loaded after clicking the button, I was no longer logged in to my account, but instead was logged in on the account of a complete stranger, who lived in the Virgin Islands. I had full access to that person's account at the www.travelsandrewards.com site.
Be careful out there.
I was using the Bank of America WorldPoints reward redemption site (www.travelsandrewards.com/) to look for some travel arrangements. I reached a page where they advised me could not accommodate my request, and provided a "Back" button to click to return and try a different itinerary.
When the page loaded after clicking the button, I was no longer logged in to my account, but instead was logged in on the account of a complete stranger, who lived in the Virgin Islands. I had full access to that person's account at the www.travelsandrewards.com site.
Be careful out there.