CVE-2020-8176: XSS
Published Jul 2, 2020
·Updated
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the shop parameter on the /shopify/auth/enablecookies endpoint.
Affected Software
2 affected components
Shopify koa-shopify-auth=3.1.61
Shopify koa-shopify-auth=3.1.62
Remediation
Patch Available
Event History
Jul 2, 2020
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-8176?
CVE-2020-8176 is classified as a cross-site scripting vulnerability, which poses a significant risk to affected applications.
2
How do I fix CVE-2020-8176?
To mitigate CVE-2020-8176, upgrade koa-shopify-auth to version 3.1.63 or later, where the vulnerability is addressed.
3
What versions of koa-shopify-auth are affected by CVE-2020-8176?
CVE-2020-8176 affects koa-shopify-auth versions 3.1.61 and 3.1.62.
4
What type of attack can exploit CVE-2020-8176?
CVE-2020-8176 can be exploited for cross-site scripting attacks by injecting malicious JavaScript payloads.
5
Where does CVE-2020-8176 occur in the application?
CVE-2020-8176 occurs on the /shopify/auth/enable_cookies endpoint when processing the shop parameter.