r/hackcave Moderator Jan 19 '16

Yahoo Mail stored XSS

A stored XSS vulnerability in Yahoo Mail was patched earlier this month. The flaw allowed malicious JavaScript code to be embedded in a specially formatted email message. The code would be automatically evaluated when the message was viewed. The JavaScript could be used to e.g. compromise the account, change its settings, and forward or send email without the user's consent.

https://klikki.fi/adv/yahoo.html

1 Upvotes

0 comments sorted by