]> git.wh0rd.org - tt-rss.git/blobdiff - include/feedbrowser.php
Prevent target='_blank' vulnerability on dynamic link
[tt-rss.git] / include / feedbrowser.php
index 4772420abb8f4cc4f0951555f0f0c193e4d717e0..ec4efe15a1e24c24f1588c237a539b8ec6322be1 100644 (file)
 
                                $class = ($feedctr % 2) ? "even" : "odd";
 
-                               $site_url = "<a target=\"_blank\"
+                               $site_url = "<a target=\"_blank\" rel=\"noopener noreferrer\"
                                                        href=\"$site_url\">
                                                        <span class=\"fb_feedTitle\">".
                                htmlspecialchars($line["title"])."</span></a>";
 
-                               $feed_url = "<a target=\"_blank\" class=\"fb_feedUrl\"
+                               $feed_url = "<a target=\"_blank\" rel=\"noopener noreferrer\" class=\"fb_feedUrl\"
                                                        href=\"$feed_url\"><img src='images/pub_set.png'
                                                        style='vertical-align : middle'></a>";
 
                                        $archived = '';
                                }
 
-                               $site_url = "<a target=\"_blank\"
+                               $site_url = "<a target=\"_blank\" rel=\"noopener noreferrer\"
                                                        href=\"$site_url\">
                                                        <span class=\"fb_feedTitle\">".
                                htmlspecialchars($line["title"])."</span></a>";
 
-                               $feed_url = "<a target=\"_blank\" class=\"fb_feedUrl\"
+                               $feed_url = "<a target=\"_blank\" rel=\"noopener noreferrer\" class=\"fb_feedUrl\"
                                                        href=\"$feed_url\"><img src='images/pub_set.png'
                                                        style='vertical-align : middle'></a>";