10K for this kind of vuln is very cheap on their part.
This is serious when you consider that they are moving millions of transactions every day...
CSRF valid for ALL users, ouch!
This is serious when you consider that they are moving millions of transactions every day...
CSRF valid for ALL users, ouch!
> We may pay beyond the range at times when bugs are found to have significant risk.
If they don't consider this a significant risk, I'm not sure what is.
[1] https://www.paypal.com/webapps/mpp/security/reporting-securi...
However a separate salaried 'cracking' team in another city, with bonuses for exploits found might work.
http://sites.miis.edu/educationinegypt/files/2013/05/CIEsala...
I think given that you could effectively steal from any account for which you knew the email was worth significantly more than 10k.
If you succeed in CSRF attack him, that is.