XSS / SELF XSS

Disclosed: 2020-09-14 19:25:10 By ferdihermawan1337 To shopify
Low
Vulnerability Details
I found xss but i think its self xss POC 1. Go to yourstore.myshopify.com 2. Go to settings > import 3. Upload wrong file csv with file name payload xss "><img src=xx onerror=alert(document.domain)> ## Impact xss attack
Actions
View on HackerOne
Report Stats
  • Report ID: 906201
  • State: Closed
  • Substate: resolved
  • Upvotes: 21
Share this report