A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the shop
parameter on the /shopify/auth/enable_cookies
endpoint.
{ "github_reviewed": true, "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed_at": "2021-05-11T18:29:58Z", "nvd_published_at": "2020-07-02T19:15:00Z" }