Unsanitized Location Name in POS Channel can lead to XSS in Orders Timeline

Disclosed: 2016-09-19 16:02:04 By nismo To shopify
Unknown
Vulnerability Details
Hi! I would like to report XSS at Shopify Admin Interface in Orders TImeline, in line Usename processes this order at NAME NAME is not sanitized and if this is set to <img src=x onerror=prompt(1)> XSS will happen ***POC*** Visit https://whitehat-3.myshopify.com/admin/orders/2253786753 or https://whitehat-3.myshopify.com/admin/orders/2253753665 XSS will trigger! Thanks!
Actions
View on HackerOne
Report Stats
  • Report ID: 166887
  • State: Closed
  • Substate: resolved
  • Upvotes: 12
Share this report