store internal email disclosed through shopify-data-exporter
Medium
S
Shopify
Submitted None
Actions:
Reported by
xenx
Vulnerability Details
Technical details and impact analysis
## Summary:
Hey Shopify,
When a store install ```shopify-data-exporter``` app to export various data of the store a link is sent to the store internal email. This internal email is disclosed via the below request to anyone
```json
GET /?shop=your_store.myshopify.com HTTP/2
Host: shopify-data-exporter.shopifycloud.com
```
{F1779393}
## Shops Used to Test:
[xentest11.myshopify.com]
## Relevant Request IDs:
[54bb78a050a2fddbc3ae360ff72d1d3e]
## Steps To Reproduce:
1. Install ```shopify-data-exporter``` in your store (```https://apps.shopify.com/data-exporter-tax-compliance```)
2. After installing the app just add your store link in ```shop``` parameter in the above shown request
3. In the response check for ```data-recipient``` attribute. It exposes the internal store email.
## Impact
Store internal email disclose to anyone in ```shopify-data-exporter.shopifycloud.com?shop=``` via ```data-recipient``` attribute
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Information Disclosure