increased privileges on staff account

Disclosed: 2020-08-24 16:05:40 By jaka-tingkir To shopify
Medium
Vulnerability Details
staff on partners without a store management permit can have access to the collaboration shop ## steps for reproduction 1. Invite staff to partners without store management permission 2. accept the invitation and the staff has become a member of the partner 3. On the staff account, try to access the collaboration store that has been active with partners 4. staff can enter and have permissions according to those owned by the partner account ## Impact gives staff unauthorized access to see anything in the collaboration shop
Actions
View on HackerOne
Report Stats
  • Report ID: 911857
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report