Stored XSS in Question edit from product name
Medium
Vulnerability Details
Hi @judgeme!
Step to reproduce:
1. Log in to your shopify account and create product with name `"><img src=x onerror=prompt(document.domain)>`
2. Go to our store and write question to our product with name `"><img src=x onerror=prompt(document.domain)>`
3. Then go to Shopify admin/Judge.me Product Reviews/Questions and edit question. XSS triage
{F1533755}
POC video:
{F1533757}
## Impact
Cookie stealer
Actions
View on HackerOneReport Stats
- Report ID: 1416672
- State: Closed
- Substate: resolved
- Upvotes: 6