Jump to content

Please remove HTMLPurifier for HTML content


Rimi

Recommended Posts

Should you not apply this patch as it is a security issue?

It's only a security issue if the admin deliberately turns on HTML posting for users that shouldn't have it.

HTML posting is designed to be only for those that truly NEED to use it and only given to those that NEED to use it. General users and/or guests should NOT have HTML posting abilities. At which point it's not a security issue.

Link to comment
Share on other sites

Guys,

We've decided to bypass HTML Purification if HTML is enabled for posts too. I've updated the KB article.

Thank you. I use "liking" as a means to bookmark certain posts, but I'm pleased enough with this to make an exception. For Marcher.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...