
PayPal Stored XSS via a Signup Flow Bypass
A stored XSS in PayPal’s account name field, delivered to arbitrary users through invoices after bypassing the signup flow’s security check by truncating the workflow URL to /webapps/.

A stored XSS in PayPal’s account name field, delivered to arbitrary users through invoices after bypassing the signup flow’s security check by truncating the workflow URL to /webapps/.