Deleted Post and Administrative Function Access in eCommerce Forum
Unknown
Vulnerability Details
Hi,
I initially queried the following report as a comment in #165048, in which @juanbroullon confirmed the issue appeared valid and requested I open a new Shopify report.
A selection of privileged information is provided upon appending `/edit` to a user profile URL on the eCommerce forum (as an authenticated user).
As such, it appears that I am able to view the user's entire history of posts as an administrator, including those which have been deleted (possibly similar to the case of #135756):
## Proof of Concept URLs
* https://ecommerce.shopify.com/users/1/edit
* https://ecommerce.shopify.com/users/1/posts
* https://ecommerce.shopify.com/users/1/posts?filter=spam
Please let me know if you require any additional details regarding this.
Thanks!
Actions
View on HackerOneReport Stats
- Report ID: 167846
- State: Closed
- Substate: resolved
- Upvotes: 6