Stored XSS in Question edit from product name

Disclosed: 2022-03-31 14:02:29 By glister To judgeme
Medium
Vulnerability Details
Hi @judgeme! Step to reproduce: 1. Log in to your shopify account and create product with name `"><img src=x onerror=prompt(document.domain)>` 2. Go to our store and write question to our product with name `"><img src=x onerror=prompt(document.domain)>` 3. Then go to Shopify admin/Judge.me Product Reviews/Questions and edit question. XSS triage {F1533755} POC video: {F1533757} ## Impact Cookie stealer
Actions
View on HackerOne
Report Stats
  • Report ID: 1416672
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report