Description
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint.
Remediation
References
https://github.com/Shopify/quilt/pull/1455
https://hackerone.com/reports/881409
Related Vulnerabilities
CVE-2021-39171 Vulnerability in npm package passport-saml
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-engine
CVE-2022-27260 Vulnerability in npm package buttercms
CVE-2020-28460 Vulnerability in npm package multi-ini
CVE-2023-35839 Vulnerability in maven package org.noear:solon.serialization.hessian