Reverse Tabnabbing Affecting quill package, versions <1.3.7


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-QUILL-460312
  • published27 Aug 2019
  • disclosed5 Jul 2019
  • creditJonathan Lloyd

Introduced: 5 Jul 2019

CVE NOT AVAILABLE CWE-1022  (opens in a new tab)

How to fix?

Upgrade quill to version 1.3.7 or higher.

Overview

quill is a modern rich text editor built for compatibility and extensibility.

Affected versions of this package are vulnerable to Reverse Tabnabbing due to use of target='_blank' in anchor tags, allowing attackers to access window.opener for the original page when opening links. This is commonly used for phishing attacks.

CVSS Scores

version 3.1