Stored XSS in Shopify Chat
Low
S
Shopify
Submitted None
Actions:
Reported by
mosuan
Vulnerability Details
Technical details and impact analysis
1.install app `Shopify Chat`
2.Click chat on the shop homepage or Shopify Ping to send poc `blocked:alert(1)//https://dqdqdqdqdq.myshopify.com`
3.Click url, alert
{F657395}
## Impact
1.Front end user Self-XSS
2.Administrator XSS foreground user
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Cross-site Scripting (XSS) - Stored