Tapatalk - Cross-Site Scripting Vulnerability

You should disable the plugin or patch the vulnerability until such a time when this is fixed. Anything that has a security vulnerability is a risk to your website.
 
Enable Debug Mode and disable the following by unchecking the box:

Screenshot 2014-05-12 22.26.26.webp

This will prevent all calls to the welcome.php file that is vulnerable.

This will allow you to keep using Tapatalk while an official patch is released. The only thing that will not work is the banner system.
 
Last edited:
Enable Debug Mode and disable the following by unchecking the box:

View attachment 73584

This will prevent all calls to the welcome.php file that is vulnerable.

This will allow you to keep using Tapatalk while an official patch is released. The only thing that will not work is the banner system.

Is it the smartbanner system that's vulnerable? I manually stripped out all of the php and js in the plugin itself awhile back for unrelated reasons. Add this to the list of stuff to check when I get home.
 
Back
Top Bottom