change Login Services settings without owner access

Disclosed: 2015-10-14 19:54:09 By supernatural To shopify
Unknown
Vulnerability Details
Hi in settings -> account owner can set login service for staff members! this is only available for owners, and full access admins can't see or change this values! admin with setting access can send a "POST" request to shop.json and change this settings! steps: - get access token for one full access admin (you can send request to xauth or sniff it from mobile device) - send request with POST method to "https://~ShopName~.myshopify.com/admin/shop.json" data: {"shop":{"google_apps_domain":"anydomain","google_apps_login_enabled":true}} google_apps_login_enabled google_apps_domain so any admin just with setting access can modify this option,this must limited to owner!
Actions
View on HackerOne
Report Stats
  • Report ID: 90690
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report