Jump to the post that solved this thread.
Thread Rating:
  • 1 Vote(s) - 3 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Solved: 4 Years, 2 Months, 3 Weeks ago Disable Avatar by URL
#11
Solved: 4 Years, 2 Months, 3 Weeks ago
Hello, it seems people still can get avatars by URL via php.

One of users managed to get custom avatar by URL even after I made button disappear.

He says this shouldn't exist :

 $mybb->input['avatarurl'] = my_strtolower($mybb->input['avatarurl']);


and there should be something like this instead

 $avatar_error = $avatar['error']

Is it correct? if so what should I change and where to make users unable to get avatars with these tricks?
Reply
#12
Solved: 4 Years, 2 Months, 3 Weeks ago
(11-24-2015, 03:41 PM)Darkrad Wrote: Hello, it seems people still can get avatars by URL via php.

One of users managed to get custom avatar by URL even after I made button disappear.

He says this shouldn't exist :

 $mybb->input['avatarurl'] = my_strtolower($mybb->input['avatarurl']);


and there should be something like this instead

 $avatar_error = $avatar['error']

Is it correct? if so what should I change and where to make users unable to get avatars with these tricks?

See this post bud.
http://community.mybb.com/thread-13483-p...l#pid89448
Reply
Jump to the post that solved this thread.


Forum Jump:


Users browsing this thread: 1 Guest(s)