embed-code-injection

1 article
sort: new top best
clear filter
0 6/10

A reflected XSS vulnerability was discovered in PayPal's ad generator tool at financing.paypal.com/ppfinportal/adGenerator where the 'size' URL parameter was reflected unsanitized into generated embed code, allowing injection of arbitrary HTML/JavaScript payloads. The vulnerability was rewarded with a $250 bounty.

PayPal Pflash Punk financing.paypal.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details