![]() |
|
Mod Options |
![]() |
|||||||||||||||||||
Remove ability for mods to use HTML in announcements
![]() Developer Last Online: Nov 2020 ![]() ![]() ![]()
Currently if someone is able to hack into one your of moderator accounts they could use it to launch a XSS attack since they could select the option to use HTML in announcements.
To fix this open modcp/announcement.php Change
to
All you are doing is commenting it out. You will need to do this each time you upload a new version of vbulletin. Download Now Only licensed members can download files, Click Here for more information. Show Your Support
The following members like this post: adwade
|
Comments |
#2
|
||||
|
||||
Thanks for posting this, but it is really not a add-on, it's a file edit.
No members have liked this post.
|
#3
|
||||
|
||||
Originally Posted by ozzy47
I understand, but I didn't see where I could post it other than the forums where it would get lost. There are no hooks in the file for me to turn it into a mod ![]()
![]() No members have liked this post.
|
#4
|
|||
|
|||
A better solution is not to give moderators permissions to post any announcements or notices.
__________________
Psychlinks Web Services Affordable Website Design & Management WordPress, vBulletin, Xenforo Customization & Management No members have liked this post.
|
![]() |
«
Previous Mod
|
Next Mod
»
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
Mod Options | |
|
|
New To Site? | Need Help? |
All times are GMT. The time now is 02:04.