View Full Version : Wysiwyg
kermit_criminal
Fri 18th Jun '04, 7:20pm
does this version of vbulletin have any security issues with the WYSIWYG editor? its a lovely feature and likely the dealbreaker that makes me shell out the cash, but i need to know if you guys have done anything to prevent maliscious html code from being inserted through posts using the WYSIWYG editor, also.. can you remove this feature be it temporarily or permanently, through the administrative control panel?
Zachery
Fri 18th Jun '04, 7:35pm
No, it has no security issues. HTML can not be used anywhere if it is disabled in the admincp. all html code is removed and outputted
<img src="tesxt.gif" alt="test" /> like so
Floris
Fri 18th Jun '04, 8:27pm
Hi there,
Thank you for your interest in the vBulletin forum software.
There are no known security issues with the WYSIWYG editor.
Please view this screenshot to see the settings for the editor as a global switch through the admin control panel > options.
kermit_criminal
Fri 18th Jun '04, 9:01pm
is it possible to allow only certain members, or groups access to wysiwyg editor? i would trust my moderators, administrators(and ME), but not regular users
Floris
Fri 18th Jun '04, 9:10pm
As mentioned before, it doesn't come with security issues. You don't have to worry about it being abused. It isn't a usergroup permission, but a global setting.
Scott MacVicar
Fri 18th Jun '04, 9:30pm
HTML is converted to bbcode before its inserted as a post, any HTML it can't convert it simply strips.
Its basically letting users use the code editor without having to worry about entering
[b]
[i]
[u]
[left / right / center]
[font="Verdana"]
[url]
[img]
etc :)
kermit_criminal
Sat 19th Jun '04, 1:16am
thanks for you help guys
vBulletin® v3.8.0, Copyright ©2000-2009, Jelsoft Enterprises Ltd.