Content Spoofing

Disclosed: 2015-05-05 15:06:26 By zerohat To shopify
Unknown
Vulnerability Details
Hi, Content Spoofing almost all in the myshopify admin account. Content Spoofing an attack technique used to trick a user into thinking that fake web site content is legitimate data. https://[YOURSHOP].myshopify.com/admin?error=CONTENT SPOOFING https://[YOURSHOP].myshopify.com/admin/orders?error=CONTENT SPOOFING https://[YOURSHOP].myshopify.com/admin/products?error=CONTENT SPOOFING https://[YOURSHOP].myshopify.com/admin/customers?error=CONTENT SPOOFING https://[YOURSHOP].myshopify.com/admin/reports?error=CONTENT SPOOFING https://[YOURSHOP].myshopify.com/admin/discounts?error=CONTENT SPOOFING https://[YOURSHOP].myshopify.com/admin/dashboard/online?error=CONTENT SPOOFING https://[YOURSHOP].myshopify.com/admin/apps?error=CONTENT SPOOFING https://[YOURSHOP].myshopify.com/admin/settings/general?error=CONTENT SPOOFING
Actions
View on HackerOne
Report Stats
  • Report ID: 58630
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report