Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a report published February 22, 2019, SecurityWeek said security researcher Jouko Pynnönen found another stored cross-site scripting (XSS) flaw in Yahoo Mail. Oath fixed the vulnerability in January 2019 and paid him $10,000. The report described potential attacks but did not publish the technical details, and it does not establish that Yahoo Mail is vulnerable today.

What happened in the Yahoo Mail XSS incident?

SecurityWeek reported that Pynnönen discovered the flaw in early December 2018. It involved HTML email filtering: according to the report, the issue was in how Yahoo Mail handled basic HTML in messages, not in attachments. Oath addressed the flaw in January 2019 and awarded Pynnönen $10,000.

The report characterized it as another stored XSS vulnerability. In a stored XSS attack, malicious content is saved or processed by a service and can run in a victim’s browser when they view affected content. In this case, SecurityWeek said a victim opening a specially crafted email could trigger the issue.

What could an attacker potentially do?

SecurityWeek described several possible consequences if an attacker succeeded: accessing or stealing the victim’s inbox, changing account settings, or causing malicious code to be added to outgoing messages. These were reported potential impacts, not evidence that attackers exploited this particular flaw in the wild.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Inbox exposure: the report said an attacker could potentially steal a user’s inbox.
  • Account changes: an attacker might alter settings, including setting up silent email forwarding.
  • Changes to outgoing mail: malicious code could potentially be added to messages sent from the account.

Why the report did not include exploit details

Oath had not authorized Pynnönen to disclose the technical details, SecurityWeek reported. As a result, the article included no proof of concept, vulnerability identifier, exact affected versions, or information sufficient to reproduce or independently inspect the exploit. The account supports a historical description of the issue, not instructions for testing an account or a conclusion about current Yahoo Mail security.

How this finding fit Pynnönen’s earlier Yahoo Mail reports

SecurityWeek placed the 2018 discovery in the context of two earlier stored XSS findings by Pynnönen. Its February 22, 2019 report said the first was found in December 2015 and earned a $10,000 bounty; roughly a year later, he found a second flaw and reportedly received another $10,000.

Finding or event What SecurityWeek reported
December 2015 Pynnönen found an earlier stored XSS flaw in Yahoo Mail and received $10,000.
Roughly a year later He found a second stored XSS flaw and reportedly earned $10,000.
Early December 2018 He discovered the flaw described in the report.
January 2019 Oath addressed the flaw and awarded him $10,000.
February 22, 2019 SecurityWeek published its report.

What Oath’s 2018 bounty figures show—and what they do not

SecurityWeek said Oath’s bug-bounty program, powered by HackerOne, paid $5 million during 2018. The company received 1,900 valid vulnerability reports, of which 300 were classified as critical or high severity. The article also reported that Oath awarded $400,000 at a one-day San Francisco event attended by 41 hackers from 11 countries.

Those are figures Oath reported for 2018, not current program terms or a rate card for future findings. The $10,000 payment in this incident likewise describes the award reported in 2019; it does not predict what another researcher would earn.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Source

Eduard Kovacs, SecurityWeek’s report on the Yahoo Mail XSS finding, published February 22, 2019.

Quick Recap

Best Value
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.