[2.0.12] persistent cross site scripting possible in field board description

Started by that-can-forum, November 03, 2016, 04:21:40 AM

Previous topic - Next topic

that-can-forum

The content in the text area desc on side area=manageboards is not validated or filtered correctly (especially chars < and "). With that you can do a CSS-attack to all users of a forum.

Illori

in SMF 2.1, you can no longer use html in that field. that should resolve this issue.

Arantor

Quote from: that-can-forum on November 03, 2016, 04:21:40 AM
The content in the text area desc on side area=manageboards is not validated or filtered correctly (especially chars < and "). With that you can do a CSS-attack to all users of a forum.

If you have that, you're probably already an admin and can XSS anyone all the time anyway. But yes, this was a known issue and is resolved in 2.1 but can't be fixed in 2.0 because users use that feature for broad descriptions that aren't just text.
Holder of controversial views, all of which my own.


Advertisement: