Description
DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.
Remediation
References
Related Vulnerabilities
Moodle Improper Access Control Vulnerability (CVE-2016-8643)
MySQL CVE-2016-0502 Vulnerability (CVE-2016-0502)
WordPress Plugin Zoho Marketing Automation SQL Injection (1.2.7)
IBM WebSEAL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1474)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-5406)