User sensitive information disclosure

Disclosed: 2020-10-22 17:28:16 By a_yang To shopify
Medium
Vulnerability Details
1、open shopify指南 Applets 2、click 个人中心 3、click 编辑资料 (微信图片_20200905123248.png) 4、https://api-wechat.shopify.cn/api/sp/customer/id (1.png) 5、Modify the ID value to traverse the user information ## Impact User sensitive information disclosur
Actions
View on HackerOne
Report Stats
  • Report ID: 975047
  • State: Closed
  • Substate: resolved
  • Upvotes: 36
Share this report