Home / Vulnerability Database / JavaScript : Unsafe target link
JavaScript
JavaScript : Unsafe target link
Classification
OWASP Top 10 2017
OWASP Top 10 2021
PCI DSS 4.0
HIPAA
Overview
The application uses links with the attribute target="_blank", which allows you to load the page by reference in a new browser window. The loaded page accesses the source page through the window.opener object. Without setting restrictions on changes to the properties of the window.opener object, it is possible to redirect the user to a phishing site.
MEDIUM
DerScanner Severity Score
Do you want to fix JavaScript : Unsafe target link in your application?
See also
JavaScript
JavaScript : Null salt
JavaScript
JavaScript : Empty encryption key
JavaScript
