fix (13838) : prevent account stealing by way of a javascript function

(cherry picked from commit 7cd05e79)

Merge request reports

Loading