Get a Pentest and security assessment of your IT network.

Cyber Security

Hackers could have stolen PayPal funds from Meetup users

Meetup is a service that enables users to create in-person or virtual events. For organizers outside the U.S., the platform offers PayPal support to charge attendees for a paid event. Researchers from Checkmarx describe a stored XSS vulnerability that allowed a regular group member to have the same permissions as an organizer. A second high-severity flaw, with a score of 8.1 out of 10, could be exploited in combination with a CSRF vulnerability to change a user s PayPal address in the Meetup profile.

Source: https://www.bleepingcomputer.com/news/security/hackers-could-have-stolen-paypal-funds-from-meetup-users/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security