XSS at importing Product List

Disclosed: 2015-06-17 15:04:11 By mafia To shopify
Unknown
Vulnerability Details
steps t reproduce: goto https://blahblah.myshopify.com/admin/products click on Import Products and upload the file in attachment and you will be able to trigger XSS
Actions
View on HackerOne
Report Stats
  • Report ID: 67125
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report