savetheinternet / Tinyboard

The better imageboard software

Home Page:http://tinyboard.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

SECURITY: XSS issue

czaks opened this issue · comments

If you are working with Tinyboard, you must apply this patch (basically remove a directory inc/lib/gettext/examples):

vichan-devel@2075437

...or else a malicious party can trick admin into a link that can exploit his or her admin rights.

Actually, it shouldn't be that easily exploitable in Chrome.