Bug Bounty

Fri
10
Oct

PayPal Inc - Mobile API vulnerable to restriction Auth Bypass Issue

PayPal Inc - Mobile API vulnerable to restriction Auth Bypass Issue

This week the vulnerability laboratory disclosed an issue in the mobile api of the paypal ios application. The issue allows remote attackers to bypass the account restriction mechanism that blocks malicious or illegal acting users.

The security vulnerability is located in the mobile api auth procedure of the paypal online-service. The mobile app api does not check for already restricted/blocked application accounts. Remote attackers are able to login through the mobile api with paypal portal restriction to access account information or interact with the compromised account.

Tue
30
Sep

PayPal Inc patched several Persistent Mail Encoding Vulnerabilities

PayPal Inc patched several Persistent Mail Encoding Vulnerabilities

During the pentests and security checks of the vulnerability laboratory against the paypal inc infrastructure the core research team discovered a lot of issues to the official bug bounty program. In the last qarters there has been several updates that prevent persistent script code executions in different paypal inc mail server online-services. The web formulars were mostly managed through the cloud services of the company and redirect the incoming mailcontext  through the connected user database.

Pages

Subscribe to RSS - Bug Bounty