Xss in website's link

Disclosed: 2015-05-13 19:26:39 By bohdansec To shopify
Unknown
Vulnerability Details
Hi, I found Xss in my website's link. Steps: Go to this page https://app.shopify.com/services/partners/account/edit In fileld "Website (optional)" add javascript:alert(document.cookie);//http://dgddfgdfgg.ua and save Need registration https://experts.shopify.com/signup After we can see account. Click link website
Actions
View on HackerOne
Report Stats
  • Report ID: 54321
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report