Unauthorized access to all collections, products, pages from other stores

Disclosed: 2015-10-20 16:00:36 By supernatural To shopify
Unknown
Vulnerability Details
Hi I found a vulnerability in shopify that can leak other shops hidden objects include collection,product,page,blog steps: - go to "/admin/link_lists" - click on "add link list" - select one object from list for example collection - open "Inspect Element" - change value of element "link_list[links][][subject_id]" to any id from other shops - click on save then when page reloaded you will see data in box this works for hidden collection, products, pages Regards
Actions
View on HackerOne
Report Stats
  • Report ID: 93921
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report