![]() |
|
HackerOne Disclosed Reports - 2025-05-15 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-05-15 (/Thread-HackerOne-Disclosed-Reports-2025-05-15) |
HackerOne disclosed reports - 2025-05-15 - hashXploiter - 05-16-2025
Medium
resolved Shopify Partners Invitation Process Allows Privilege Escalation Without Email VerificationBug reported by Ahmed Ghallab was disclosed at May 15, 2025, 6:25 pm | Improper Access Control - Generic The Shopify Partners invitation process allowed privilege escalation without email verification. The vulnerability permitted unauthorized users to gain access to Shopify Partners accounts and escalate their privileges by creating accounts using the email addresses of invited owners and accepting the invitations.
Low
resolved Corrupted pointer in node::fs::ReadFileUtf8(const FunctionCallbackInfo |