Blog | G5 Cyber Security

PayPal addresses reflected XSS bug in user wallet currency converter

PayPal has fixed a reflected cross-site scripting (XSS) vulnerability that was discovered in the currency converter feature of user wallets. The vulnerability was reported by the bug bounty hunter Cr33pb0y through the HackerOne platform. The flaw was caused by a failure to properly sanitize the input in a parameter in the URL. The malicious script will execute in the browser page DOM of another user typically without their knowledge or consent. PayPal has implemented additional validation checks and sanitizer controls for user input.”]

Source: https://securityaffairs.co/wordpress/114570/hacking/paypal-reflected-xss-wallet.html

Exit mobile version