Loading HuntDB...

Stored XSS in Shopify Chat

Low
S
Shopify
Submitted None
Reported by mosuan

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Stored
1.install app `Shopify Chat` 2.Click chat on the shop homepage or Shopify Ping to send poc `blocked:alert(1)//https://dqdqdqdqdq.myshopify.com` 3.Click url, alert {F657395} ## Impact 1.Front end user Self-XSS 2.Administrator XSS foreground user

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$500.00

Submitted

Weakness

Cross-site Scripting (XSS) - Stored