Stored XSS in Question edit from product name
Medium
J
Judge.me
Submitted None
Actions:
Reported by
glister
Vulnerability Details
Technical details and impact analysis
Hi @judgeme!
Step to reproduce:
1. Log in to your shopify account and create product with name `"><img src=x onerror=prompt(document.domain)>`
2. Go to our store and write question to our product with name `"><img src=x onerror=prompt(document.domain)>`
3. Then go to Shopify admin/Judge.me Product Reviews/Questions and edit question. XSS triage
{F1533755}
POC video:
{F1533757}
## Impact
Cookie stealer
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Cross-site Scripting (XSS) - Stored