PayPal has fixed a security vulnerability that could have been exploited to send malicious emails to users via its platform. Researchers at security firm Vulnerability Lab have discovered a filter bypass and an application-side input validation vulnerability that allowed attackers to inject malicious code into emails sent by the PayPal platform. The vulnerability was reported to PayPal in October 2015, the vulnerability has been fixed this month. The company awarded the researcher Kunz Mejri with $1,000, the details of the flaw were disclosed on Wednesday. The attacker could be exploited in phishing campaigns, session hijacking, and to redirect users to certain domains managed by the attackers.”]
Source: http://securityaffairs.co/wordpress/45796/hacking/paypal-flaw-send-malicious-emails.html

