GHSA-jqh7-w5pr-cr56
MODERATECVE-2020-8176A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the shop parameter on the /shopify/auth/enablecookies endpoint.
- Affected
- >= 3.1.61, <= 3.1.62
- Fixed in
- 3.1.63
- Weakness
- CWE-79
- Published
- 2021-05-17
- Source
- github