Skip to main content

Stored XSS

XSS via XML File Upload on PayPal

·1 min read

PayPal’s invoicing feature accepted .xml attachments, and an XHTML-namespaced script element inside the XML executed when the file was served back. Includes the exploitability argument needed to qualify it for a bounty.

Stored XSS File upload XML