Alibaba 's team has fixed a serious security issue on one of its e-commerce portals that exposed account details of thousands of merchants and buyers to cybercriminals.
An Israeli security firm, AppSec Labs, has found a Cross site scripting (XSS) vulnerability in AliExpress, the English version of the e-commerce company's site, which was found vulnerable to similar security holes a week ago, putting Alibaba customers' personal information at risk .The problem was fixed immediately after it was reported to the companyby Cybermoon.
AliExpress, an online marketplace owned by Chinese e-commerce giant Alibaba.com, also known as the Google of China, serves over 300 million active users from more than 200 countries, including the US, Russia and Brazil. The critical vulnerability found by the researcher could allow an attacker to break into any merchant's account.
Any attacker could put any payload script as a variable in the message, and when the seller would go to the message center on the AliExpress website, using his account, the malicious script would run in the user's browser. He could also perform actions on behalf of the seller, phishing, steal the victim's identification information, etc.
The vulnerability was discovered by Barak Tawily, a 21-year-old application security researcher at AppSec Labs. By exploiting the vulnerability, he was able to change product prices, delete merchandise, and even close the merchant's store on the website, without the merchant knowing anything.
