All reports
mediumLogic errorOther

Window.opener bug at www.coinbase.com

Payout
$100
Protocol
coinbase
Disclosed
Nov 28, 2016
Source
hackerone

A web application link on www.coinbase.com opened external URLs using target="_blank" without setting the rel="noopener" or rel="noreferrer" security attributes. This allowed the newly opened destination window to access and manipulate the parent tab through t …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.