Loading HuntDB...

Missing rel=noreferrer tag allows link in list to change url of currently open tab

I
Instacart
Submitted None
Reported by cablej

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
Hi, When adding links to lists, there is no rel=noreferrer tag present, allowing a linked page to change the url of the currently open tab. This can open the doors for phishing attacks, as users trust the tab that contained instacart. As an example, see my list at https://inst.cr/t/1QmLPG. Clicking the link, which opens in a new tab, will change the url of the currently open tab to http://example.com. Thank you for your time, and please let me know if you have any questions.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Violation of Secure Design Principles