Entrance Chat Gallery Guilds Search Everyone Wiki Login Register

Welcome, Guest. Please login or register. - Thinking of joining the forum??
March 21, 2026 - @159.57 (what is this?)
Activity rating: Three Stars Posts & Arts: 31/1k.beats Unread Topics | Unread Replies | My Stuff | Random Topic | Recent Posts Start New Topic  Submit Art
News: Love is not possession  :4u: Guild Events: There are no events!

+  MelonLand Forum
|-+  Forum Hub
| |-+  ⛄︎ ∙ MelonLand Info & Questions
| | |-+  BUG WATCH! - If you see a bug report it here!


« previous next »
Pages: 1 ... 15 16 [17] Print
Author Topic: BUG WATCH! - If you see a bug report it here!  (Read 56307 times)
Melooon
Hero Member ⚓︎
*****
View Profile WWWArt


So many stars!
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: melon
iMood: Melonking
Itch.io: My Games
RSS: RSS

Guild Memberships:
Artifacts:
Flinstone Vitaminold-timey tunes~♪Always working hard!PoochKnown Apple shillcoolest melon on the web!
« Reply #240 on: February 26, 2026 @551.10 »

the welcome email it's suggested to write a greeting, but the link leads to a board where no
Thanks for the report! This is so weird, I've fixed this bug at least 3 times and somehow that link never goes away, it must be in some other file somewhere :drat:
Logged


everything lost will be recovered, when you drift into the arms of the undiscovered

Artifact Swap: Air MailPhoenix DownRoachLasagna
Dan Q
Sr. Member ⚓︎
****
View Profile WWWArt


I have no idea what I am doing
⛺︎ My Room
RSS: RSS

Guild Memberships:
« Reply #241 on: March 13, 2026 @402.88 »

I'm moderately confident there's an XSS vulnerability in the code that puts a message in the shoutbox when somebody creates a new thread.

When you create a new thread, the title of that thread gets posted (in a link) to the shoutbox, e.g. "Dan Q created [linked title of post]".

But that title doesn't get escaped, so any HTML code in the post title gets injected directly into the page, via the shoutbox. I haven't tested it, but a Melonlander could (deliberately or accidentally) cause a problem here. Suppose I created a thread with the subject "<script>alert('hi');</script> not working on my site", then I imagine the actual HTML code <script>alert('hi');</script> would get injected into the shoutbox!

We're a closed community, so we're probably moderately-safe (or else I wouldn't announce this in a public thread!), but it's probably still worth fixing! All that's needed is to run the titles through an escape_html(...) -like function before shoutboxing them.

I discovered this by accident when I posted this thread, which has HTML-like code in the subject.

Update: yup, verified by this thread, with which I was able to inject an image into the shoutbox. The limitation on the lengths of subject strings would make an "attack" difficult, but definitely not impossible! See attached screenshot.


* xss-in-the-shoutbox-demo.webp (23.98 kB, 537x303 - viewed 5 times.)
« Last Edit: March 13, 2026 @408.25 by Dan Q » Logged


Artifact Swap: PolyamorousI met Dan Q on Melonland!Joined 2025!Lurby
pepper
Full Member ⚓︎
***
View Profile WWWArt


she/her 🐾 local furry punk
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: mildlypepper

Guild Memberships:
Artifacts:
Joined 2025!
« Reply #242 on: March 15, 2026 @143.18 »

This is a very odd issue but whenever I leave the forum page open in a tab and I restart my browser I get pinged notifications for alerts I have already seen and viewed.

This'll be because new alerts get picked up by each tab, but alerts that you click on only trigger an event in the current tab. And your browser is caching the DOM. I guess.
...
Refreshing the page should make them go away (because you've already viewed them).
...

This happens to me frequently, and reloading the page doesn't seem to make it go away completely? I have been getting the same notifications popping up on my OS toasts since Wednesday, across two different PCs/ browsers, even though I do not have any alerts showing on the forum.

Both PCs are Linux Mint, both are up-to-date Firefox. I am having difficulty recreating the problem reliably, but I have been for instance getting notifications about the Wednesday Website guild off and on since Wednesday. Even if I close my browser, then later re-open it, I will sometimes (but not always?) get the same notifications.

For the time being I think I will need to just disable notifications for the forum, which is a shame as I like knowing when threads I'm interested in have activity, I don't like to clutter my email inbox, and I have yet to set up an RSS client. (Maybe I should just set up an RSS client already, but still, this bug ... bugs me ...)
Logged

  :dog:  I'm verbose. Sorry! (not sorry)

         
boreal_cryptid
Sr. Member ⚓︎
****
View Profile WWWArt


без надії сподіваюсь
⛺︎ My Room

Guild Memberships:
Artifacts:
john egbertPolyamorousLucky Cat Companion +10 Dmg +5 luck +5 Stealthfaceplant neko^_^Joined 2025!
« Reply #243 on: March 15, 2026 @168.50 »

mobile version of the forum doesn't hide/spoiler users from ignore list :(
Logged

Is this how you honor MelonLand Forum, and the tribe unmourned? Write to me openly, and not by stealth.

Artifact Swap: green leaf (for outdoors enjoyers)snowy (for winter lovers)
Melooon
Hero Member ⚓︎
*****
View Profile WWWArt


So many stars!
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: melon
iMood: Melonking
Itch.io: My Games
RSS: RSS

Guild Memberships:
Artifacts:
Flinstone Vitaminold-timey tunes~♪Always working hard!PoochKnown Apple shillcoolest melon on the web!
« Reply #244 on: March 15, 2026 @180.82 »

Both PCs are Linux Mint, both are up-to-date Firefox. I am having difficulty recreating the problem reliably
I have noticed this too, almost every time I open the forum on a computer I've not used in a while it will spam all the past notifications since I last used it, even for things I've already viewed on other computers. I don't really know much about how browser notifications work, so I have no idea why that happens! I guess its possible that push notifications are always running in the background, so the browser stacks up notifications quietly, maybe there is some command that should be sent to clear them. If anyone has experience lemmy know, otherwise it'll need some research!

hide/spoiler users from ignore list :(
It could be a chicken and egg situation; but less than 1% of forum members have ever used the ignore feature, so this is prob not a part of the site that's gonna get much time dedicated to it, but I will add it to the list! :ziped:
Logged


everything lost will be recovered, when you drift into the arms of the undiscovered

Artifact Swap: Air MailPhoenix DownRoachLasagna
Melooon
Hero Member ⚓︎
*****
View Profile WWWArt


So many stars!
⛺︎ My Room
SpaceHey: Friend Me!
StatusCafe: melon
iMood: Melonking
Itch.io: My Games
RSS: RSS

Guild Memberships:
Artifacts:
Flinstone Vitaminold-timey tunes~♪Always working hard!PoochKnown Apple shillcoolest melon on the web!
« Reply #245 on: March 17, 2026 @782.41 »

moderately confident there's an XSS
across two different PCs/ browsers, even though I do not have any alerts showing on the forum.
Both these should be fixed now. Alerts are prob still weird, but I'm 99% sure you will only get alerts in one tab now, and I'm 50% sure you wont get alerts showing up across multiple computers/browsers unless both are awake and on the forum at the moment you get an alert. (however its also possible I just broke notifications completely)

Dan your XSS attack path should now be fixed, hope you made some good use of it while you could :grin:
Logged


everything lost will be recovered, when you drift into the arms of the undiscovered

Artifact Swap: Air MailPhoenix DownRoachLasagna
Dan Q
Sr. Member ⚓︎
****
View Profile WWWArt


I have no idea what I am doing
⛺︎ My Room
RSS: RSS

Guild Memberships:
« Reply #246 on: March 18, 2026 @489.17 »

Dan your XSS attack path should now be fixed, hope you made some good use of it while you could :grin:

Ah, give me a few weeks; I'm sure I'll stumble upon another! :tongue:
Logged


Artifact Swap: PolyamorousI met Dan Q on Melonland!Joined 2025!Lurby
Pages: 1 ... 15 16 [17] Print 
« previous next »
 

Melonking.Net © Always and ever was! SMF 2.0.19 | SMF © 2021 | Privacy Notice | ~ Send Feedback ~ Forum Guide | Rules | RSS | WAP | Mobile


MelonLand Badges and Other Melon Sites!

MelonLand Project! Visit the MelonLand Forum! Support the Forum
Visit Melonking.Net! Visit the Gif Gallery! Pixel Sea TamaNOTchi