*.shopify.com - Authentication bypass

Disclosed: 2020-08-24 16:18:08 By nooblife To shopify
Unknown
Vulnerability Details
I´ve found a flaw in the authentication process when accessing the website https://upcoming.shopify.com. There seems to be an HTTP Authentication in place to prevent access without authentication. Please follow below POC to get access to https://upcoming.shopify.com without login. The website is full with weird behavior and i´m able to register new accounts via https://upcoming.shopify.com. That could maybe lead to some internal issues. ***Normal request*** {F772305} ***POC** 1) Go to: https://upcoming.shopify.com/tools 2) From that point you can travel to any endpoint {F772313} {F772314} {F772315} ## Impact High
Actions
View on HackerOne
Report Stats
  • Report ID: 838231
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report