Researcher Awarded $10,000 for Disclosing Critical XSS Vulnerability in Yahoo Mail

A Finland based security researcher named Jouko Pynnönen awarded $10,000 for disclosing critical cross-site scripting (XSS) vulnerability in the webmail version of Yahoo Email service.

An attacker could exploit the vulnerability to compromise the victim accounts, change their email settings and to perform other malicious activities.

The vulnerability resides in the webmail version of the Yahoo service that failed to filter the malicious code in HTML emails.

Pynnönen reported the bug to Yahoo in early December 2018 and the bug was fixed by Yahoo in January and the researcher doesn’t disclose any technical details and he was awarded $10,000 for this bug.

Training Course: Web Hacking and Bug Bounty – Get started in Bug Bounty Program

This is not the first time Pynnönen find’s stored XSS in Yahoo mail, early he discovered a stored XSS in December 2015, which allows an attacker to send a maliciously crafted email with hidden JavaScript code that would get executed once the victim reads the message.

One year later he found another stored XSS vulnerability with the web version of the Yahoo Mail service due to improper sanitization of codes in HTML emails.

DOM-based XSS Vulnerability Affected 685 Million Users of Tinder, Shopify, Western Union, and Imgur

Top 500 Most Important XSS Script Cheat Sheet for Web Application Penetration Testing

Guru baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus Labs, the leading Web3 security infrastructure provider, has unveiled a groundbreaking report highlighting the growing, widespread use and potential…

12 hours ago

C2A Security’s EVSec Risk Management and Automation Platform Gains Automotive Industry Favor as Companies Pursue Regulatory Compliance

In 2023, C2A Security added multiple OEMs and Tier 1s to its portfolio of customers, successful evaluations, and partnerships such…

13 hours ago

Wireshark 4.2.4 Released: What’s New!

Wireshark stands as the undisputed leader, offering unparalleled tools for troubleshooting, analysis, development, and education. The latest update, Wireshark 4.2.4,…

16 hours ago

Zoom Unveils AI-Powered All-In-One AI Work Workplace

Zoom has taken a monumental leap forward by introducing Zoom Workplace, an all-encompassing AI-powered platform designed to redefine how we…

16 hours ago

iPhone Users Beware! Darcula Phishing Service Attacking Via iMessage

Phishing allows hackers to exploit human vulnerabilities and trick users into revealing sensitive information and grant unauthorized access. It's an…

17 hours ago

2 Chrome Zero-Days Exploited at Pwn2Own 2024: Patch Now

Google has announced a crucial update to its Chrome browser, addressing several vulnerabilities, including two zero-day exploits showcased at the…

20 hours ago