HackerOne Disclosed Reports - 2025-03-20

0 Replies, 306 Views

Logo
Medium
resolved

Limited Privilege User Can Create Unauthorized Referrals on partners.shopify.com


Bug reported by Samuel was disclosed at March 20, 2025, 8:23 pm   |   Improper Access Control - Generic

A privilege escalation vulnerability was discovered in Shopify's Partner Portal that allowed users without the "View referrals" permission to create POS leads by directly accessing the lead creation URL. The backend API lacked proper authorization checks, enabling users to bypass the restrictions implemented in the user interface and submit referrals without the necessary permissions.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)