
A stored XSS vulnerability, which could be easily used by hackers as an entry point for further attacks, was discovered and reported to PayPal by BitDefender researchers.
[signoff icon=”icon-target”]In stored XSS attacks, attackers use malicious URLs, specially designed to store the exploit code on the server. This is done with the help of a blog comment, a forum post, a database entry, and so on. When a user accesses a page where the attack code has been “stored”, then that specific piece of code is loaded into their browser and executed.[/signoff]
The BitDefender team revealed the existence of an XSS vulnerability in the PayPal customer dashboard, and more specifically in the Request Money -> Create Invoice section.
According to researcher Liviu Arsene, the vulnerability lies in the way URLs are encrypted by PayPal's system when users upload files in the "Create Invoice" section.
XSS vulnerability could have been exploited to distribute malicious content
By exploiting this vulnerability, attackers would be able to replace PayPal output files with “~test.bat” files instead of invoices. Attackers could control the contents of these files, distributing malware or using them as an entry point for further attacks.
Since the files come from PayPal's servers, unsuspecting users would have no hesitation in opening the .bat files, thinking that it was an invoice stored in some "strange" format.
After identifying the security flaw, antivirus company Bitdefender worked closely with PayPal staff and the vulnerability was successfully patched.
Just a week ago, PayPal patched yet another stored XSS vulnerability, which could have exposed users' personal information to attackers.

