Categories: SecurityWorkspace

PayPal Defends Denying 17-Year-Old His Bug Bounty

PayPal has given two reasons why a 17-year-old was not rewarded for finding a potentially serious vulnerability on the payment platform’s website: he was not old enough and the flaw had already been found.

German student Robert Kugler decided to disclose the cross-site scripting (XSS) vulnerability on Seclists.Org after PayPal turned him away.

He found the vulnerability in the search function of the site, triggering it with some JavaScript code, as is normal with XSS flaws. Such attacks typically see a hacker send the victim a link, which will have them enter JavaScript code into the vulnerable website form. That code would include a command to pass cookies on to the hacker’s own domain.

“I don’t want to allege PayPal a kind of bug bounty cost saving, but it’s not the best idea when you’re interested in motivated security researcher,” he wrote.

PayPal defence

The eBay-owned company came in for some stick on Reddit, where one user noted Google and Mozilla pay under-age participants if they get an adult’s permission. Given the lack of security talent available globally, companies should reward youngsters for their findings, according to security experts.

But PayPal has defended its actions. “While we appreciate Mr. Kugler’s contribution to PayPal’s Bug Bounty Program, we can confirm that the cross-scripting vulnerability he identified was already discovered by another security researcher and Mr. Kugler is ineligible to participate in the program since he is under 18 years old,” a spokesperson said, in an emailed statement sent to TechWeekEurope.

“We are working quickly to fix the cross-scripting issue, and we have not found any evidence at this time that our customers’ information has been compromised by this vulnerability.

“We recognise and appreciate Mr. Kugler’s efforts, and we look forward to continue working with the security community to receive bug submissions that are responsibly disclosed.”

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Is the Digital Transformation of Businesses Complete?

Digital transformation is an ongoing journey, requiring continuous adaptation, strong leadership, and skilled talent to…

16 hours ago

Craig Wright Faces Contempt Claim Over Bitcoin Lawsuit

Australian computer scientist faces contempt-of-court claim after suing Jack Dorsey's Block and Bitcoin Core developers…

17 hours ago

OpenAI Adds ChatGPT Search Features

OpenAI's ChatGPT gets search features, putting it in direct competition with Microsoft and Google, amidst…

17 hours ago

Google Maps Steers Into Local Information With AI Chat

New Google Maps allows users to ask for detailed information on local spots, adds AI-summarised…

18 hours ago

Huawei Sees Sales Surge, But Profits Fall

US-sanctioned Huawei sees sales surge in first three quarters of 2024 on domestic smartphone popularity,…

18 hours ago

Apple Posts China Sales Decline, Ramping Pressure On AI Strategy

Apple posts slight decline in China sales for fourth quarter, as Tim Cook negotiates to…

19 hours ago