Lack of interest Any reason why Notices allow HTML?

This suggestion has been closed automatically because it did not receive enough votes over an extended period of time. If you wish to see this, please search for an open suggestion and, if you don't find any, post a new one.

arn

Well-known member
Was curious about this. Is there a reason why Notices allow HTML?

Seems a potential security hole. This is the vector through which Ubuntu Forums as well as MacRumors forums were hacked under vB. Moderator account was broken into (shared/weak passwords), and an HTML announcement was posted. That HTML announcement then allowed the hacker to escalate Admin access by use of an external javascript.

I realize in XF the notices are an admin priviledge, but you could still imagine giving some admins notice access, but not other access.

I guess my suggestion would be to not allowed HTML in notices, or have it disable-able.

arn
 
Upvote 0
This suggestion has been closed. Votes are no longer accepted.
HTML is allowed in other areas such as page nodes, custom bb code, etc.

If you're going to remove it from notices then logically you would have to remove it from everywhere, which would drastically reduce the functionality of the software.
 
Back
Top Bottom