Categories > WeAreDevs > Announcements >
There was never an XSS issue with the previous code blocks
Posted
You used to be able to create code blocks by enclosing text between two sets of three backticks "```". There was a bug with the implementation that sometimes caused a page to display a bit funky. People confused this for an XSS vulnerability. I want to say that there was no XSS vulnerability. The real cause was that the server would prematurely close an HTML tag due to the way the server inserts the code blocks. It was a semantics issue. There was no way to insert Javascript code as a result of this bug.
I've removed the old implementation of code blocks because I saw that the editor had a plugin that already implements code blocks. This spared my time of needing to fix the bug. It also implemented code blocks way better.
If I'm wrong and someone has proof that it caused XSS issues, then please let me know. Otherwise, I'm absolutely confident that the previous code block implementation issue was just a visual bug.
Replied
print("very poggers")
https://i.gyazo.com/18ca88edbb1c5917deae116065088a21.png
was this u mean? (thanks to david btw)
Cancel
Post
https://media.discordapp.net/attachments/1010636204225601659/1012865624797610044/sKQybOLT.gif
Replied
I failed🥺🥺🥺🥺🥺ðŸ˜ðŸ˜ðŸ˜ðŸ˜ðŸ˜ªðŸ˜“😓😢😢
Content length must be 10-5000 chars
Cancel
Post
https://media.discordapp.net/attachments/1010636204225601659/1012865624797610044/sKQybOLT.gif
Replied
Did you ever find out why only my thread did that?
Cancel
Post
Discord : Doctor Doom#0550
Replied
console.warn("jon is our senpai and is caring about us!!")
OMFG THESE CODE BLOCKS ARE EVEN SECKSIERRR
Cancel
Post
JustMarie#0709
Â
Replied
@Moon Yeah. I explained it above.
The server would prematurely close an HTML tag due to the way the server inserts the code blocks.
Cancel
Post
Replied
ok, good to know
Cancel
Post
Replied
console.log("Very Informative!");
Cancel
Post
Replied
no idea what any of this is about but hello
:DDD
Cancel
Post
Replied
listen to jon man
Cancel
Post
Added
Fix wrd bot btw it is bugged i cant get the active forumer badge the bot is late
Cancel
Post
no
Error: The signature must be between 3-200 characters
Users viewing this thread:
( Members: 0, Guests: 1, Total: 1 )
Cancel
Post