Cross-site scripting (XSS) flaws are among the most commonly encountered security flaws found on websites. The flaw could easily have been abused to redirect web browsers to a phishing page, or to serve up content designed to infect visiting computers with a drive-by malware attack. Amazon doesnt pay a bug bounty and vulnerability researchers should be doing the work of Amazons security team for nothing, says white hat hacker Brute Logic. BruteLogic found that sites including Worthing Herald were at risk from the XSS flaw.”]
Source: https://grahamcluley.com/xss-flaws-expose-weaknesses-on-amazon-and-uk-newspaper-websites/

