← Back to CVE List

CVE-2020-8176

Published: 2020-07-02T19:15Z
Last Modified: 2024-11-21T05:38Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt