XSS on postal codes
Medium
S
Shopify
Submitted None
Actions:
Reported by
pappan
Vulnerability Details
Technical details and impact analysis
Hi,
#190951 is not fully fixed. Scripts can be injected via a csv file and make it execute in the application. Screenshots attached.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic