From d8b0f06705812ef9e4ee4b1943f53dd82743db19 Mon Sep 17 00:00:00 2001 From: JustAMacUser Date: Sat, 6 Aug 2016 14:07:30 -0400 Subject: [PATCH] Remove href attribute if it executes JavaScript. --- include/functions2.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/include/functions2.php b/include/functions2.php index aab73d342..dceea507e 100644 --- a/include/functions2.php +++ b/include/functions2.php @@ -1064,6 +1064,10 @@ array_push($attrs_to_remove, $attr); } + if ($attr->nodeName == 'href' && stripos($attr->value, 'javascript:') === 0) { + array_push($attrs_to_remove, $attr); + } + if (in_array($attr->nodeName, $disallowed_attributes)) { array_push($attrs_to_remove, $attr); }