Hacker News new | ask | show | jobs
by HiJon89 2303 days ago
For #5 I believe it's not just a self-XSS, but also executes on the support agents browser, allowing you to potentially exfiltrate their cookies:

> Anyone can write malicious code into the chatbox and PayPal’s system would execute it. Using the right payload, a scammer can capture customer support agent session cookies and access their account.

1 comments

Yeah, they probably should have included a POC of the attack on initial submit. That one got patched after the N/A. That's pretty sad.

For example, under example quality reports, POCs are provided

https://hackerone.com/reports/32825

https://docs.hackerone.com/programs/quality-reports.html