XSS in creating tweets

Disclosed: 2015-12-03 22:02:26 By haxs101 To shopify
Unknown
Vulnerability Details
Hi, I found an XSS while tweeting my product. To reproduce: * Create new tweet. * Select any product. * Input in message content `"><img src=x onerror=alert(document.domain)> * XSS executes. * Hit Publish. XSS also executes. Cheers!
Actions
View on HackerOne
Report Stats
  • Report ID: 101450
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report