diff options
author | Jérémy DECOOL <[email protected]> | 2017-02-12 11:01:36 +0100 |
---|---|---|
committer | Jérémy DECOOL <[email protected]> | 2017-02-12 11:01:36 +0100 |
commit | ba2853caac636d2ae596d74561fa0233567242d4 (patch) | |
tree | 9e46eabafcddd2e76cd0c8fc4c1498d0b1858757 /classes/pref | |
parent | 2187322caee25756d28983f069e291612023c6dc (diff) |
Prevent target='_blank' vulnerability on dynamic link
Diffstat (limited to 'classes/pref')
-rw-r--r-- | classes/pref/prefs.php | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/classes/pref/prefs.php b/classes/pref/prefs.php index 9a7ab55a0..ece9e8078 100644 --- a/classes/pref/prefs.php +++ b/classes/pref/prefs.php @@ -776,7 +776,7 @@ class Pref_Prefs extends Handler_Protected { print "<td><label><img src='images/$plugin_icon' alt=''> $name</label></td>"; print "<td>" . htmlspecialchars($about[1]); if (@$about[4]) { - print " — <a target=\"_blank\" class=\"visibleLink\" + print " — <a target=\"_blank\" rel=\"noopener noreferrer\" class=\"visibleLink\" href=\"".htmlspecialchars($about[4])."\">".__("more info")."</a>"; } print "</td>"; @@ -835,7 +835,7 @@ class Pref_Prefs extends Handler_Protected { print "<td><label for='FPCHK-$name'><img src='images/$plugin_icon' alt=''> $name</label></td>"; print "<td><label for='FPCHK-$name'>" . htmlspecialchars($about[1]) . "</label>"; if (@$about[4]) { - print " — <a target=\"_blank\" class=\"visibleLink\" + print " — <a target=\"_blank\" rel=\"noopener noreferrer\" class=\"visibleLink\" href=\"".htmlspecialchars($about[4])."\">".__("more info")."</a>"; } print "</td>"; |