Exposed Slinky Instance Admin Panel

Disclosed: 2021-01-16 06:07:40 By rhynorater To shopify
None
Vulnerability Details
Last night the following server went from a 404 to a 200: ███████ Upon navigating to this page, I found that there was a slinky admin panel available here with the ability to change and modify URL redirection. ``` https://slinky-server.shopifycloud.com/ ``` ## Impact Ability to modify potentially trusted URL redirects
Actions
View on HackerOne
Report Stats
  • Report ID: 808762
  • State: Closed
  • Substate: resolved
  • Upvotes: 38
Share this report