Stored XSS in the Shopify Discussion Forums

Disclosed: 2015-05-31 14:54:43 By singh_sukhjiwan To shopify
Unknown
Vulnerability Details
Hi Shopify Security Team, There is Stored XSS in the Shopify Discussion Forums.Under ecommerce.shopify.com, in shopify-discussion The STORED XSS is present. The Stored XSS can easily be produced Every time. To Produce the XSS Vulnerability, I created a New Topic Under the shopify-discussions in the Forums.I entered this XSS PAYLOAD in TITLE "><img src=x onerror=prompt(1)> Now I entered demo content in the Message box,and clicked on create the topic, then topic has been created. It shows Our topic and below that shows two options EDIT POST and ATTACH IMAGE. From this attach image option i attached the image and uploaded to the topic. When i clicked the Image to enlarge it the STORED XSS executed itself and pop up was generated. Here are steps to Reproduce the Stored XSS Bug: Enter the shopify-discussion under the Shopify Discussion Forums and create a new topic. In title add xss payload: "><img src=x onerror=prompt(1)> and in the message box and any demo content, and create the topic. After the topic has been created it shows the two options EDIT POST and Attach image, upload any from the this options. Now after the upload click the image to enlarge image,the XSS payload in the title will be executed. Please find attached the Proof of Concept, i am attaching the screenshots. Thank u Regards, Sukhjiwan Singh
Actions
View on HackerOne
Report Stats
  • Report ID: 59015
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report