Filtered by vendor Shopify Subscriptions
Filtered by product Koa-shopify-auth Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-8176 1 Shopify 1 Koa-shopify-auth 2024-08-04 6.1 Medium
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint.