Steffen
Well-known member
- Affected version
- 2.0.2
vBulletin allows saving a signature with BBCode even if its usage is forbidden. The [IMG] BBCode will just be ignored later on while rendering the signature.
XenForo automatically removes [IMG] BBCode while saving a signature. It does not seem to check whether [IMG] BBCode is allowed while rendering the signature (the renderer seems to accept whatever was saved).
The resulting problem is that users imported from vB4 can have a signature with [IMG] BBCode (which actually gets rendered) although its usage is forbidden.
The importer should automatically remove [IMG] BBCode from signatures if its usage is forbidden. Or the renderer should check the permissions.
PS: Maybe this affects other BBCodes, too?
XenForo automatically removes [IMG] BBCode while saving a signature. It does not seem to check whether [IMG] BBCode is allowed while rendering the signature (the renderer seems to accept whatever was saved).
The resulting problem is that users imported from vB4 can have a signature with [IMG] BBCode (which actually gets rendered) although its usage is forbidden.
The importer should automatically remove [IMG] BBCode from signatures if its usage is forbidden. Or the renderer should check the permissions.
PS: Maybe this affects other BBCodes, too?