It looks like you're new here. If you want to get involved, click one of these buttons!
http://bot24.blogspot.com/2012/06/vanilla-forums-version-20184-with-poll.html
http://www.henryhoggard.co.uk/security/vanilla-poll-stored-xss/
Yikes... I use this plugin, but fortunately only my moderators have the permissions to create polls.
I feel like I happened on this thread just by luck... I wish there was a more formal and prominent place where security flaws in the Vanilla ecosystem are announced.
Yeah, someone should change the title of this thread to "SECURITY WARNING for Polls plugin" or something
Answers
No problem -- the subject line is terrible, don't know what possessed me to write something like that -- should be "SECURITY WARNING".
- Spam
- Abuse
- Troll
2 • Off Topic Insightful 2Awesome LOL •here's a suggested change to the code to prevent the xss mentioned in this exploit. http://www.henryhoggard.co.uk/security/vanilla-poll-stored-xss/
here is a suggested security fix to the poll plugin
factoid: Most questions have been previously answered, try the search box first, please provide your Vanilla version Number!
Peregrine's Addons - donations gladly accepted for "successful solutions" and addons - kind of like tipping a waiter at a restaurant
- Spam
- Abuse
- Troll
0 • Off Topic Insightful Awesome LOL •