Blog
Yahoo! Mail Patches Stored XSS Vulnerability, Awards Researcher $10,000
By David Bisson on Wed, 01/20/2016
Yahoo Mail! has patched a stored cross-site scripting (XSS) vulnerability and awarded a researcher $10,000 for finding the flaw. Discovered by Finnish researcher Jouko Pynnonen, the bug allowed an attacker to embed malicious Javascript code into a specially crafted email. The code would automatically execute whenever the message was viewed,...