DEV Community

Discussion on: The target="_blank" vulnerability by example

Collapse
 
shostarsson profile image
Rémi Lavedrine

That is brilliant post.
Very well explained. I didn't know that vulnerability.

This article has some real life examples.
And now you can imagine some really bad attack.
I redirect to a Facebook like website I own that said "You've been disconnected, please reconnect". And boom, you have the user password.
Just brilliant.

So it is just vital to add the noopener value.