Stored XSS in Question edit for product name (bypass #1416672)

Disclosed: 2022-03-31 14:01:04 By glister To judgeme
Medium
Vulnerability Details
Hi @judgeme! Step to reproduce: 1. Log in to your shopify account and create product with name `"><"><img src=x onerror=prompt(document.domain)> img src=x onerror=prompt(document.domain)>` 2. Go to our store and write question to our product with name `"><"><img src=x onerror=prompt(document.domain)> img src=x onerror=prompt(document.domain)>` 3. Then delete our product from store (The product status must be (out of store) in questions. 4. Then go to Shopify admin/Judge.me Product Reviews/Questions and edit question. XSS triage {F1547145} POC video {F1547181} ## Impact session stealer
Actions
View on HackerOne
Report Stats
  • Report ID: 1428207
  • State: Closed
  • Substate: resolved
  • Upvotes: 10
Share this report