shopifyapps.com XSS on sales channels via currency formatting

Disclosed: 2015-12-14 19:10:36 By reactors08 To shopify
Unknown
Vulnerability Details
pinterest, twitter, buy button and facebook sales channels vulnerable to xss via currency formatting. steps to reproduce: - remove pinterest, twitter, buy button and facebook sales channels at *.myshopify.com/admin/channels - go to *.myshopify.com/admin/settings/general - change currency formating as shown at the `currency_formatting.jpg`(check attachment) - add pinterest, twitter, buy button and facebook sales channels at *.myshopify.com/admin/channels - check pinterest, twitter and buy button tabs - create collection and add a product to it (skip this step if you already have collection with product) - go to facebook tab --> shop ( `*.myshopify.com/admin/apps/shopify-facebook/collections` )
Actions
View on HackerOne
Report Stats
  • Report ID: 104359
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report