Rafay Baloch explained that the bug he had reported was very critical in nature and carried a high amount of risk to the PayPal as an attacker could have easily managed to execute any command on the server and manipulate the data at his will. He said that he had been paid $500 for an XSS vulnerability that he found on PayPal's main domain, in addition to $500 for an information disclosure. Rafay has reported 20 bugs which are still being validated by PayPal. According to him, PayPal has offered him job in lately. However, he said that he has not decided in this regard mainly due to his continued studies.
Rafay Baloch explained that the bug he had reported was very critical in nature and carried a high amount of risk to the PayPal as an attacker could have easily managed to execute any command on the server and manipulate the data at his will. He said that he had been paid $500 for an XSS vulnerability that he found on PayPal's main domain, in addition to $500 for an information disclosure. Rafay has reported 20 bugs which are still being validated by PayPal. According to him, PayPal has offered him job in lately. However, he said that he has not decided in this regard mainly due to his continued studies.