MyBB Community Forums

Full Version: Mybb 1.6.3 XSS Vulnerability
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2
There should be an option to control what HTML can be used if enabled.
I believe someone made a HTML Purifier script. If you're going to use HTML in posts, you probably need to run that plugin.
^Here it is:
http://mods.mybb.com/view/htmlpurifier

I use it along HTML In Posts to limit the usage of HTML just for some members.
Pages: 1 2