Score
Jump to scoreCalculator
Bug Bounty Severity Calculator

Attack Vector
Select what type of vector
Attack Complexity
Measurable effort to exploit
Merchants: Extensive knowledge of target merchant, specific shop configuration, etc.; Shopify: Multiple post-exploitation steps, significant recon, overcoming mitigations/detections, etc.
Vector's value:
Low
Privileges Required
Requires privileged account
Merchants: requires an account on target shop or partners organization; Shopify: requires access to account to claim subdomain/rubygem, etc.
Does the attacker need extensive permissions?
Merchants: Self-registered accounts are not considered privileged in this context. Requires powerful permission, such as the "Settings" permission; Shopify: Requires access to restricted or beta features, sandboxed environment, etc.
Vector's value:
None
User Interaction
Victim performs an action during exploit?
Eg. Click link or button, perform Shopify ID account merge, etc.
Vector's value:
None
Scope Change
Can the attacker impact a separate service?
Merchants: Using Partners to access arbitrary stores; Shopify: Lateral movement to other network services
Vector's value:
Unchanged
Confidentiality
Data impact?
If the data impacted is sensitive in nature or includes PII, choose High
Does this impact scale to the rest of the service?
For example, in the case of Shopify, could this vector be reasonably scaled to impact any arbitrary Store or does the vector limit the impact to a subset of Stores?
Vector's value:
None
Integrity
Data impact?
If the data impacted is sensitive in nature or includes PII, choose High
Does this impact scale to the rest of the service?
For example, in the case of Shopify, could this vector be reasonably scaled to impact any arbitrary Store or does the vector limit the impact to a subset of Stores?
Vector's value:
None
Availability
Level of disruption to network service?
How much of the service is impacted?
Merchants: How many merchants? Shopify: How many services? If any are core, choose Most or All
Vector's value:
None
Environment
Score
Score
0.0
Bounty
$ 0
*Not scalable to most or all of Shopify
Severity
None
Vector String
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N