Yahoo patches critical XSS vulnerability that would allow hackers to read any email
Yahoo, which was in the limelight for revealing a massive hack on its users earlier this year, has fixed a highly critical cross-site scripting (XSS) security flaw in its email system that would have allowed attackers to access any email.
The flaw was discovered and reported by Finland-based security researcher Jouko Pynnonen who earned $10,000 for the feat from Yahoo's bug bounty program. The flaw allowed an attacker to read a victim's email or create a virus infecting Yahoo Mail accounts among other things.
Unlike other email phishing scams and ransomware attacks, there is no need for the hacker to send a virus or trick the victim into clicking a specific link. Attackers would just send a mail to victims to access their emails. Last year, Pynnonen had reported a serious bug for Yahoo that allowed an attacker to take over any user's account by using the same XSS vulnerability. According to him the impact of this bug was the same as last year's XSS issue.