Skip to content

Unsafe use of target blank vulnerability fix (powered by Mobb)#297

Open
anatolimobb wants to merge 1 commit intomainfrom
Mobb-fix-1a00a10d35
Open

Unsafe use of target blank vulnerability fix (powered by Mobb)#297
anatolimobb wants to merge 1 commit intomainfrom
Mobb-fix-1a00a10d35

Conversation

@anatolimobb
Copy link
Owner

This change fixes a low severity (🟢) Unsafe use of target blank issue reported by Checkmarx.

Issue description

Unsafe Target Blank occurs when developers use the target='_blank' attribute without the rel='noopener' attribute in anchor tags. This can lead to security vulnerabilities such as tabnabbing or reverse tabnabbing, allowing attackers to hijack user sessions or perform phishing attacks.

Fix instructions

Ensure that anchor tags with target='_blank' attribute include the rel='noopener' attribute to prevent potential security vulnerabilities. This prevents the newly opened page from accessing the window.opener property, mitigating the risk of tabnabbing or reverse tabnabbing attacks.

More info and fix customization are available in the Mobb platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant