Cross-Site Scripting Vulnerability in Koa-Shopify-Auth by Shopify
CVE-2020-8176

6.1MEDIUM

Key Information:

Vendor

Shopify

Vendor
CVE Published:
2 July 2020

What is CVE-2020-8176?

A Cross-Site Scripting (XSS) vulnerability in Koa-Shopify-Auth versions 3.1.61 to 3.1.62 allows attackers to inject JavaScript payloads via the shop parameter in the /shopify/auth/enable_cookies endpoint. This security flaw could be exploited to execute arbitrary scripts in the context of an authenticated user, posing significant risks to the confidentiality and integrity of user data. Organizations should apply necessary patches and update their implementations to mitigate the risks associated with this vulnerability.

Affected Version(s)

koa-shopify-auth Impacted: v3.1.61-v3.1.62, Fixed: v3.1.63

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.