OSV 1.4.0 · github-reviewed · 修改于 2022-09-10 04:01
发布时间
2021-05-18 05:01
GitHub 审查时间
2021-05-12 02:29
NVD 发布时间
2020-07-03 03:15
源文件
advisories/github-reviewed/2021/05/GHSA-jqh7-w5pr-cr56/GHSA-jqh7-w5pr-cr56.json
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the shop parameter on the /shopify/auth/enable_cookies endpoint.