Reflected XSS on $Any$.myshopify.com/admin
High
S
Shopify
Submitted None
Actions:
Reported by
dr_dragon
Vulnerability Details
Technical details and impact analysis
# Description :
Hi,
I have found a reflected cross site scripting vulnerability in <any>.myshopify.com/admin through return_url parameter .
# Step to reproduce :
1-Go to https://<Any>.myshopify.com/admin/authenticate?return_url=blocked:alert(100)//
2-Click on reload this page
3-Xss alert message
## Impact
Xss attack in <Any>.myshopify.com/admin
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$1500.00
Submitted
Weakness
Cross-site Scripting (XSS) - Reflected