Entrance Chat Gallery Guilds Search Everyone Wiki Login Register

Welcome, Guest. Please login or register. - Thinking of joining the forum??
March 13, 2026 - @802.96 (what is this?)
Activity rating: Three Stars Posts & Arts: 44/1k.beats Unread Topics | Unread Replies | My Stuff | Random Topic | Recent Posts Start New Topic  Submit Art
News: :happy: Open the all windows! Your mind needs storms and air! :happy: Guild Events: There are no events!

+  MelonLand Forum
|-+  Forum Hub
| |-+  ⛄︎ ∙ MelonLand Info & Questions
| | |-+  BUG WATCH! - If you see a bug report it here!


« previous next »
Pages: 1 ... 15 16 [17] Print
Author Topic: BUG WATCH! - If you see a bug report it here!  (Read 55906 times)
Melooon
Hero Member ⚓︎
*****
View Profile WWWArt


So many stars!
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: melon
iMood: Melonking
Itch.io: My Games
RSS: RSS

Guild Memberships:
Artifacts:
Flinstone Vitaminold-timey tunes~♪Always working hard!PoochKnown Apple shillcoolest melon on the web!
« Reply #240 on: February 26, 2026 @551.10 »

the welcome email it's suggested to write a greeting, but the link leads to a board where no
Thanks for the report! This is so weird, I've fixed this bug at least 3 times and somehow that link never goes away, it must be in some other file somewhere :drat:
Logged


everything lost will be recovered, when you drift into the arms of the undiscovered

Artifact Swap: Air MailPhoenix DownWorm CreatureRoachLasagna
Dan Q
Sr. Member ⚓︎
****
View Profile WWWArt


I have no idea what I am doing
⛺︎ My Room
RSS: RSS

Guild Memberships:
« Reply #241 on: Today at @402.88 »

I'm moderately confident there's an XSS vulnerability in the code that puts a message in the shoutbox when somebody creates a new thread.

When you create a new thread, the title of that thread gets posted (in a link) to the shoutbox, e.g. "Dan Q created [linked title of post]".

But that title doesn't get escaped, so any HTML code in the post title gets injected directly into the page, via the shoutbox. I haven't tested it, but a Melonlander could (deliberately or accidentally) cause a problem here. Suppose I created a thread with the subject "<script>alert('hi');</script> not working on my site", then I imagine the actual HTML code <script>alert('hi');</script> would get injected into the shoutbox!

We're a closed community, so we're probably moderately-safe (or else I wouldn't announce this in a public thread!), but it's probably still worth fixing! All that's needed is to run the titles through an escape_html(...) -like function before shoutboxing them.

I discovered this by accident when I posted this thread, which has HTML-like code in the subject.

Update: yup, verified by this thread, with which I was able to inject an image into the shoutbox. The limitation on the lengths of subject strings would make an "attack" difficult, but definitely not impossible! See attached screenshot.


* xss-in-the-shoutbox-demo.webp (23.98 kB, 537x303 - viewed 2 times.)
« Last Edit: Today at @408.25 by Dan Q » Logged


Artifact Swap: PolyamorousI met Dan Q on Melonland!Joined 2025!Lurby
Pages: 1 ... 15 16 [17] Print 
« previous next »
 

Melonking.Net © Always and ever was! SMF 2.0.19 | SMF © 2021 | Privacy Notice | ~ Send Feedback ~ Forum Guide | Rules | RSS | WAP | Mobile


MelonLand Badges and Other Melon Sites!

MelonLand Project! Visit the MelonLand Forum! Support the Forum
Visit Melonking.Net! Visit the Gif Gallery! Pixel Sea TamaNOTchi