Vulnerabilities/

Reverse Tabnabbing in quill

Severity:
Medium

Description

Versions of quill prior to 1.3.7 are vulnerable to Reverse Tabnabbing. The package uses target='_blank' in anchor tags, allowing attackers to access window.opener for the original page when opening links. This is commonly used for phishing attacks.

Recommendation

Update the quill package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
quill
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing