As Designed Bug found in demo

Discussion in 'Resolved Bug Reports' started by Tah Zonemaster, Sep 2, 2011.

  1. ragtek

    ragtek

    Descriptions can contain HTML
    IMO it's not a bug if you include "wrong HTML :D".

    It's the same as if you change a template and delete everything, or include not valid elements;)
  2. Brogan

    Brogan

    Board Meta Description
    Edit: I see you mean forum description, not board description. Specifically this forum: http://demo.xenforo.com/104/index.php?forums/test.3/

    As ragtek posted above, it must be valid HTML.
  3. Thanks for your replies both. It's not just using </div>, I can place <script> tags too, which work when loading the page. I know you can do this with templates too, but boards should have a check IMO.
  4. ragtek

    ragtek

    1.Only admins can create/edit these things, so if somebody wants to "destroy/hack" something, he will be able to do this even the data are validated...
    2. IMO it's really usable that we're able to use HTML there

    My 0.02$
    Daracon and Darkimmortal like this.
  5. Brogan

    Brogan


    I use HTML to display the moderators in each category, amongst other things.
    It's also used here on XenForo.com in the customer forums.

    XenForo Community Support
    You must be a XenForo customer to post in these forums. Ensure your account is listed here.
  6. Floris

    Floris

    Exploit your own board as full admin by setting the description to <script>alert('naughty');</script> and feel like a king for a second.
    Bob likes this.
  7. ibnesayeed

    ibnesayeed

    You may also set the forum description as:



  8. kkm323

    kkm323

    ohh god this demo is so missy
  9. Mike

    Mike

    As mentioned, this is as designed and documented.

