DEV Community

Discussion on: The target="_blank" vulnerability by example

Collapse
 
f763rod profile image
f763rod

Is this vulnerability only exploited on pages where users submit or upload information? The reason I'm asking, a site I'm assisting, uses target="_blank" on many pages but most of the pages are only displaying information and user's are not submitting or uploading content.

Collapse
 
ben profile image
Ben Halpern

It's only really a thing if you can't fully trust the pages you're linking out to. And as described, there are ways to mitigate this to a good extent.