Software
PayPal patches account hijacking flaw
Reported by itnews.com.au
Payments giant PayPal has patched a flaw that allowed hackers access into any customer account through a targeted attack.As part of PayPal’s bug bounty program, Egyptian researcher Yassar H Ali discovered a cross-site request forgery (CSRF) flaw that allowed attackers to take over control of any PayPal account if they were successful in convincing a target to click on a link.