Deleted Post and Administrative Function Access in eCommerce Forum

Disclosed: 2016-10-05 21:10:10 By ysx To shopify
Unknown
Vulnerability Details
Hi, I initially queried the following report as a comment in #165048, in which @juanbroullon confirmed the issue appeared valid and requested I open a new Shopify report. A selection of privileged information is provided upon appending `/edit` to a user profile URL on the eCommerce forum (as an authenticated user). As such, it appears that I am able to view the user's entire history of posts as an administrator, including those which have been deleted (possibly similar to the case of #135756): ## Proof of Concept URLs * https://ecommerce.shopify.com/users/1/edit * https://ecommerce.shopify.com/users/1/posts * https://ecommerce.shopify.com/users/1/posts?filter=spam Please let me know if you require any additional details regarding this. Thanks!
Actions
View on HackerOne
Report Stats
  • Report ID: 167846
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report