Skip to main content

Research

2026

2020

2016

2015

XSS via XML File Upload on PayPal

·1 min read

PayPal’s invoicing feature accepted .xml attachments, and an XHTML-namespaced script element inside the XML executed when the file was served back. Includes the exploitability argument needed to qualify it for a bounty.

Stored XSS File upload XML

2014

2013