logo

How a Cross-Site Scripting Vulnerability Led to Account Takeover

ID: 1314de1a-36a0-53b8-8bdb-a0fa3fca1e4f

STIX ID: report--1314de1a-36a0-53b8-8bdb-a0fa3fca1e4f

Feed Name: HackerOne Blog

Threat Score
50/100

Date Published: 2024-11-27

Date Updated: 2026-06-12

...
...

This report describes Cross-Site Scripting (XSS) — its reflected, stored, and DOM variants — common causes, impacts (including session theft and account takeover), and mitigations such as input validation, output encoding, and Content Security Policy. It includes a HackerOne-disclosed reflected XSS in yelp.com that could enable persistent XSS and account takeover via manipulated cookie values, notes the $6,000 bounty awarded, and recommends bug bounty/PTaaS and secure coding practices to find and fix XSS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.