G

check use of target="_blank"

target="_blank" can lead to phishing issue by changing the originating page, cf. this article: https://dev.to/ben/the-targetblank-vulnerability-by-example This should be checked in external HTML in libervia (or directly in backend, check that target is not an allowed attribute).
id

150

author

Goffi

created

10. 9. 2016 11:24

updated

10. 9. 2016 11:24

labels
Libervia
type
bug
status
queued
priority
normal
milestone
0.7
severity
major