Open Redirect - www.shopify.com

Disclosed: 2020-07-14 21:15:20 By zonduu To shopify
Low
Vulnerability Details
Hello Shopify team, I found an open redirect in www.shopify.com Link: - `https://www.shopify.com/plus/get-cdn-asset?asset=http://evil.com/?` **Vulnerable parameter:** `asset` ## Impact - Open redirect that can lead to phishing and other type of attacks. Have a good day, zonduu.
Actions
View on HackerOne
Report Stats
  • Report ID: 905737
  • State: Closed
  • Substate: resolved
  • Upvotes: 17
Share this report