Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
When a link opens a URL in a new tab with target="_blank", it is very simple for the opened page to change the location of the original page because the JavaScript variable window.opener is not null and thus "window.opener.location can be set by the opened page. This exposes the user to very simple phishing attacks.
- Loading branch information