filename-injection

1 article
sort: new top best
clear filter
0 7/10

A researcher demonstrated how to escalate self-XSS into non-self stored XSS on PayPal's Technical Support and Brand Central portals by exploiting inadequate file content validation (allowing malicious SVG files) and authorization issues that permitted unauthenticated users to submit tickets to registered accounts. The vulnerability enabled attackers to inject malicious scripts that would execute when support staff or authorized users accessed the tickets.

PayPal paypal-techsupport.com paypal-brandcentral.com YoKo Kho BruteLogic
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details