3 ms·
For #5 I believe it's not just a self-XSS, but also executes on the support agents browser, allowing you to potentially exfiltrate their cookies: > Anyone can
by HiJon89 7y ago
For #5 I believe it's not just a self-XSS, but also executes on the support agents browser, allowing you to potentially exfiltrate their cookies:
> Anyone can write malicious code into the chatbox and PayPal’s system would execute it. Using the right payload, a scammer can capture customer support agent session cookies and access their account.
- blazespin 7y agoYeah, they probably should have included a POC of the attack on initial submit. That one got patched after the N/A. That's pretty sad. For example, under example quality reports, POCs are provided https://hackerone.com/reports/32825 https://hackerone.com/reports/32825 https://docs.hackerone.com/programs/quality-reports.html https://docs.hackerone.com/programs/quality-reports.html