On Monday, we learned that a DOM-based cross-site scripting (XSS) found by Yahoo! could be exploited by cybercriminals to gain access to user accounts. Yahoo! announced shortly after that the vulnerability had been fixed, but security experts are now coming out to deny it.
Security researcher Shahin Ramezany, who first discovered the vulnerability, and researchers from Offensive Security have found that with a slight modification to the original attack method, the vulnerability still exists and can be exploited if an attacker convinces the victim to click on a link containing malicious code.
The researchers have even released a new video that provides evidence of what they claim. The sensitive technical details have been redacted:

