Security researcher Prakhar Prasad discovered a Blind SQL Injection vulnerability on PayPal 's notification website (paypal-notify.com). The company immediately fixed the vulnerability and rewarded the expert with $3,000.
“This bug allowed me to access PayPal’s notification system database,” the researcher explains in his blog.
“I disclosed the bug to Paypal's security team and the issue was immediately addressed, with the vulnerability being fixed the very next day,” he added.
This is another example of how bug bounty programs can help an organization maintain a secure website.
📧
Subscribe to the SecNews Newsletter

