Session works after logout from Shopify account and password of online store is displayed

Disclosed: 2020-04-27 16:09:54 By premium101 To shopify
Low
Vulnerability Details
When a user creates a Shopify Lite Plan account, in the product creation stage when the account has not been upgraded, the store's password is enabled such that any visitor who wants to access the store is required to enter password before being granted access to view the products listed in the online store. When a logout request has been made and response has been received/displayed that logout is successful, session still works when https://unctify.myshopify.com/accounts/passwords is entered in the browser url address bar; the resulting Shopify page displays the password required to enter the store which is supposed to be visible to only the admin and those who have been sent this password. Please see the PoC attached. ## Impact Third party can view the listed products and also exploit the user session vulnerability.
Actions
View on HackerOne
Report Stats
  • Report ID: 837729
  • State: Closed
  • Substate: resolved
  • Upvotes: 154
Share this report