Skip to main content
An enclosed industrial conveyor running from open ground straight into the side of a large plant building.
Photo by Martin Adams on Unsplash
  1. Archive/

DOM XSS on PayPal's Main Domain

Patrik Grobshäuser
Author
Patrik Grobshäuser
Security researcher at Assetnote / Searchlight Cyber. Before that, seven years triaging other people’s reports at HackerOne and Shopify. Hunting bugs since 2012, published as Patrik Fehrenbach until 2025.
Table of Contents

I recently discovered a DOM cross-site scripting issue while testing PayPal. The process was straightforward — inserting this payload into the URL was enough:

#"><img src=/ onerror=alert(2)>

Impact
#

The DOM executed the JavaScript straight from the URL. This vulnerability would have affected all registered PayPal users. The report was closed as a duplicate, but I wanted to write it up anyway.

Disclosure
#

Here’s the PoC I sent to the PayPal bug bounty team.

— Patrik Grobshäuser

Related