News and Notes from the Makers of Nexus | Sonatype Blog

Persistent Flaws in PayPal Allow Cybercriminals to Hijack User Sessions and More

Written by Ali Loney | October 02, 2012

Softpedia – (International) Persistent flaws in PayPal allow cybercriminals to hijack user sessions and more. Vulnerability lab researchers have identified multiple web vulnerabilities on the official PayPal website, Softpedia reported October 2. A remote attacker could have exploited the high-severity security holes against Pro, seller, or regular customer accounts. A persistent input validation vulnerability is detected in the official PayPal e-commerce website content management system (Customer/Pro/Seller). The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent) of the PayPal web service.

Source: http://news.softpedia.com/news/Persistent-Flaws-in-PayPal-Allow-Cybercriminals-to-Hijack-User-Sessions-and-More-296107.shtml