Digital garden

Home

❯

case study

❯

bughunt

❯

web_bug

❯

hackerone shopify 2020 09 l 906201

hackerone-shopify-2020-09-l-906201

Feb 04, 20261 min read

hackerone-shopify-2020-09-l-906201

XSS / SELF XSS

보고서

  1. <<내 상점>>.myshopify.com 로 간다.
  2. settings > import로 간다.
  3. CSV 파일 이름을 "><img src=xx onerror=alert(document.domain)> 로 지정하여 올린다.

tags: bughunting, shopify, xss, stored-xss, wstg-inpv-02, severity low, web hacking


Graph View

  • hackerone-shopify-2020-09-l-906201
  • XSS / SELF XSS

Created with Quartz v4.5.1 © 2026

  • Blog