November 2018
Beginner to intermediate
270 pages
7h 53m
English
On October 5th, 2015, a security researcher named Dhaval Chauhan reported a vulnerability in Shopify's code.
This vulnerability affected the application, after the user was logged into the application. Then, there are two possible consequences.
The first consequence is related to the following URL:
http://ecommerce.shopify.com/accounts?found_email=true&return_to=.mx%2F&user%5Bemail%5D=email@email.com
Once the user enters their email in the URL, they are redirected to the Mexican site, which is determined by the mx value in the return_to parameter. This parameter can be manipulated, allowing us to redirect the user to other extensions in the domain, or to complete different domains to steal their data.
The other ...
Read now
Unlock full access