MyBB Community Forums

Full Version: Sanitizing code from external/official sources
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
To prevent issues like this from happening in the future, the code that is being fetched from external sources and then displayed on ACP pages should be properly sanitized - especially given that the official MyBB websites do not serve requests over HTTPS.

It might put an end to cloning the MyBB Blog on Check for Updates page, but displaying plaintext entry titles with links to original entries does not sound so bad when security is at stake.
It has already been planned: https://github.com/mybb/mybb/issues/1617 Also, the accounts will be surely more secured.