Self xss in product reviews

Disclosed: 2020-11-19 23:29:16 By tomorrow_future To shopify
Medium
Vulnerability Details
1、install app `Product Reviews` {F1070556} 2、Open a product and write a review 3、Press F12 on the keyboard,Change the type of email to text. 4、Write in email`"><img src=a onerror=alert(1)>[email protected]`. {F1070565} 5、Write other required fields,then submit. {F1070566} ## Impact Self xss
Actions
View on HackerOne
Report Stats
  • Report ID: 1029668
  • State: Closed
  • Substate: resolved
  • Upvotes: 29
Share this report