Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →LinkedIn fixed a persistent cross-site scripting (XSS) flaw in its Help Center within three hours of being notified on November 16, 2015, according to a contemporaneous SecurityWeek report. The flaw was reported in the Help Center’s “Start a Discussion” form: malicious code entered in its “more details” field could be saved in a post and run when someone later opened that post.
What was the LinkedIn Help Center XSS flaw?
Security researcher Rohit Dua found the issue in the “more details” field of LinkedIn’s Help Center “Start a Discussion” page, SecurityWeek reported. An attacker could publish a post containing malicious code. Because the post retained the payload, it could execute when another person viewed the post in the Help Center or clicked a link directing them to it.
That saved-and-later-executed behavior is what makes this a stored or persistent XSS issue. In reflected XSS, by contrast, the payload is returned in a response to a request rather than retained as application content for later views. SecurityWeek’s account describes the retained-post behavior, but does not provide a technical advisory or patch diff.
How quickly did LinkedIn fix it?
Dua reported the flaw to LinkedIn on November 16, 2015. SecurityWeek said LinkedIn patched it within three hours of notification. The report does not identify the exact filtering or sanitization error that made the input exploitable, or explain what code LinkedIn changed, so a more specific root cause cannot be established from that account.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
What impact was confirmed?
The report does not establish that attackers exploited the flaw in the wild. Dua described the possibility of taking actions as a target user and of the vulnerability spreading like a worm as potential impact; these were not reported as confirmed outcomes. SecurityWeek’s account also does not establish a CVE identifier, severity score, or independent exploitation statistics for this incident.
How does LinkedIn handle vulnerability reports now?
LinkedIn’s current Security Vulnerabilities help page directs security researchers to submit vulnerability notifications through HackerOne and asks them to keep details private until a fix is released. It directs reports of spam or phishing to the relevant LinkedIn email addresses instead. The policy may change, so check LinkedIn’s page before making a report.
Rank #2
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
- There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
- Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
- Reorder SKU: LOG-100-M3CW-PP(Security-Report)
What did LinkedIn say about its bug bounty program?
SecurityWeek reported that LinkedIn had a private bug bounty program at the time. By June 2015, the company had reportedly paid more than $65,000 for 65 security holes; this is a historical total, not a current bounty budget or rate. In November 2015, LinkedIn director of information security Cory Scott told SecurityWeek: “We did evaluate creating a public bug bounty program. However, based on our experience handling external bug reports and our observations of the public bug bounty ecosystem we believe the cost-to-value of these programs no longer fit the aspirational goals they originally had.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What remains unknown about the 2015 incident?
The available incident account is SecurityWeek’s report, rather than an original LinkedIn advisory or Dua’s technical write-up. It does not establish the vulnerable implementation, the patch details, whether the flaw was exploited, or whether the old Help Center feature or implementation still exists today. The 2015 incident should therefore be understood as a historical vulnerability response, not evidence that LinkedIn is currently vulnerable.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Best Value
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

