Instead of closing one of the top 10 most common web vulnerabilities on its site, Yahoo has said that an open direct flaw is ‘working as designed’.