mediumLogic errorOther
Window.opener bug at www.coinbase.com
- Payout
- $100
- Protocol
- coinbase
- Disclosed
- Nov 28, 2016
- Source
- hackerone
A web application link on www.coinbase.com opened external URLs using target="_blank" without setting the rel="noopener" or rel="noreferrer" security attributes. This allowed the newly opened destination window to access and manipulate the parent tab through t …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.