G

check use of target="_blank"

target="_blank" can lead to phishing issue by changing the originating page, cf. this article: https://dev.to/ben/the-targetblank-vulnerability-by-example This should be checked in external HTML in libervia (or directly in backend, check that target is not an allowed attribute).
id

150

author

Goffi

created

10/09/2016, 11:24

updated

10/09/2016, 11:24

labels
Libervia
type
bug
status
queued
priority
normal
milestone
0.7
severity
major