The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Scanner Check For target="_blank" Vulnerability

Surreal | Last updated: Sep 01, 2016 04:41PM UTC

Hi Portswigger, I would like to see a check added for links with target="_blank" without the rel="noopener noreferrer" attribute. The author of the below article demonstrates that the site which is linked to is able to control the location of the page containing the original link using window.opener. https://dev.to/ben/the-targetblank-vulnerability-by-example Thank you

PortSwigger Agent | Last updated: Sep 07, 2016 10:20AM UTC