Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For #5 I believe it's not just a self-XSS, but also executes on the support agents browser, allowing you to potentially exfiltrate their cookies:

> Anyone can write malicious code into the chatbox and PayPal’s system would execute it. Using the right payload, a scammer can capture customer support agent session cookies and access their account.



Yeah, they probably should have included a POC of the attack on initial submit. That one got patched after the N/A. That's pretty sad.

For example, under example quality reports, POCs are provided

https://hackerone.com/reports/32825

https://docs.hackerone.com/programs/quality-reports.html




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: