Vulnerability In PayPal worth 200000$ bounty, Attacker can Steal Your Balance by One-Click

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Vulnerability In PayPal worth 200000$ bounty, Attacker can Steal Your Balance by One-Click

Post by Shane1145 »

7 months ago this was reported as security issue to PayPal bug bounty program where the attacker can steal users' money by exploiting Clickjacking,

Clickjacking, also known as a “UI redress attack”, is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top level page. Thus, the attacker is “hijacking” clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both. reference: https://owasp.org/www-community/attacks/Clickjacking


Post Reply