Open Redirect after login at http://ecommerce.shopify.com

Disclosed: 2015-10-05 18:38:33 By dhaval To shopify
Unknown
Vulnerability Details
Hi, The users can be redirected to some other site which is in control of the attacker from http://ecommerce.shopify.com/accounts Let's say user is attacker asked victim to login from the here : http://ecommerce.shopify.com/accounts?found_email=true&return_to=.mx%2F&user[email][email protected] When victim enters the password he is redirected to http://ecommerce.shopify.com.mx/ This com.mx can be changed to multiple like .es .tw etc These can be controlled by the attacker and used in other attacks
Actions
View on HackerOne
Report Stats
  • Report ID: 55546
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report