Possible cross site scripting issue with HTML enabled

Общие вопросы по HТМЛ, CSS и phpbb3 от пользователей форума
Ответить
jackneeson
Сообщения: 4
Зарегистрирован: 19 июн 2018, 12:29
Репутация: 0
Пол: Мужской

Possible cross site scripting issue with HTML enabled

Сообщение jackneeson » 25 июн 2018, 17:48

Hello,

For those people operating phpBB with HTML enabled we have been notified by Marvin Massih of a possible cross site scripting issue. It will affect primarily those who have enabled the <a> (anchor tag) but it may impact certain other tags too depending on what functionality they offer. The problem occurs because users may enter "javascript:" within a given url ... which can of course be used to grab local cookie (for example) information from the client. At this time we advise everyone with HTML enabled to remove the a tag from the list of allowed tags (Admin Panel -> General -> Configuration -> Allowed tags). There really is no reason to allow the anchor tag anyway, BBCode provides appropriate functionality for linking. We will continue looking at potential solutions to this but it isn't necessarily a straightforward issue to solve without impacting the very functionality the <a> tag can give you (same applies to any other tag that may be affected). Of course our advice remains, as it always has, to only enable HTML if you positively, absolutely have no alternative. There are various BBCode Mods available here and elsewhere which offer the functionality of a number of common HTML tags ... while reducing considerably the risk of layout and privacy issues.

Please help

I didn't find the right solution from the internet.

References:
Скрытое содержимое
Вы должны быть зарегистрированным пользователем, чтобы прочитать это содержимое.


Thank you

Ответить
  • Похожие темы
    Ответы
    Просмотры
    Последнее сообщение

Вернуться в «Вопросы от пользователей»