Order notifications being sent for a deactivated staff account

Disclosed: 2018-04-12 08:20:21 By newbie_101 To shopify
Low
Vulnerability Details
Hi, Steps to reproduce : - - Have a staff account with settings permission - The staff account can go to notifications & add himself so as to get new order notifications - Now,deactivate the staff account via the admin. - Create a new order,you shall see that the staff still receives the order notification via email. - This happens because the account still exists,but if staff deleted , then there is no account,hence no email) so no notification. ## Impact - Info disclosure about a customer of a store the staff account cant have access to.
Actions
View on HackerOne
Report Stats
  • Report ID: 331223
  • State: Closed
  • Substate: resolved
  • Upvotes: 16
Share this report