New link opening method makes hackerone vulnerable to tabnabbing

Disclosed: 2021-07-07 08:49:31 By recon_ninja To security
Low
Vulnerability Details
**Summary:** Hackerone recently changed how it opens the external links and this new way is vulnerable to tabnabbing. **Description:** Please see the POC. ### Steps To Reproduce 1. Click here: https://awasthi7.github.io/ 2. Click on proceed when warning appears. 3. The site will open in new tab and hackerone tab will be replaced by Google. ### Optional: Your Environment (Browser version, Device, etc) * ### Optional: Supporting Material/References (Screenshots) * ## Impact Unvalidated redirect
Actions
View on HackerOne
Report Stats
  • Report ID: 1159398
  • State: Closed
  • Substate: resolved
  • Upvotes: 50
Share this report