A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the shop
parameter on the /shopify/auth/enable_cookies
endpoint.
{ "github_reviewed": true, "github_reviewed_at": "2021-05-11T18:29:58Z", "cwe_ids": [ "CWE-79" ], "nvd_published_at": "2020-07-02T19:15:00Z", "severity": "MODERATE" }