---
title: "PayPal patches account hijacking flaw"
url: "https://thecybersecurityplace.com/paypal-patches-account-hijacking-flaw/"
date: "2014-12-04T04:56:46+00:00"
section: "Software"
tags:
  - "Software Security"
source: "itnews.com.au"
source_url: "http://www.itnews.com.au/News/398496,paypal-patches-account-hijacking-flaw.aspx?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+"
---

# PayPal patches account hijacking flaw

December 4, 2014 · Reported by itnews.com.au

> Payments giant PayPal has patched a flaw that allowed hackers access into any customer account through a targeted attack.As part of PayPal’s bug bounty program, Egyptian researcher Yassar H Ali discovered a cross-site request forgery (CSRF) flaw that allowed attackers to take over control of any PayPal account if they were successful in convincing a target to click on a link.

[Read the full article at itnews.com.au](http://www.itnews.com.au/News/398496,paypal-patches-account-hijacking-flaw.aspx?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+)

**Tags:** [Software Security](https://thecybersecurityplace.com/tag/software-security/)
