Loading HuntDB...

Stored XSS in Question edit from product name

Medium
J
Judge.me
Submitted None
Reported by glister

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
Hi @judgeme! Step to reproduce: 1. Log in to your shopify account and create product with name `"><img src=x onerror=prompt(document.domain)>` 2. Go to our store and write question to our product with name `"><img src=x onerror=prompt(document.domain)>` 3. Then go to Shopify admin/Judge.me Product Reviews/Questions and edit question. XSS triage {F1533755} POC video: {F1533757} ## Impact Cookie stealer

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$500.00

Submitted

Weakness

Cross-site Scripting (XSS) - Stored