Minecraft PC IP: play.cubecraft.net

Rifyy

Well-Known Member
Aug 19, 2019
95
334
104
If you embed an image you can edit the style attribute and set the width to whatever you like. there is still a wrapper element for the displayed image so you cant make it bigger than default but you can make it smaller

upload_2020-5-16_23-46-53.png


I inserted the image element manually with element inspect too, might make a difference

I doubt this is the only XSS vulnerability, all events seem to be blocked by cloudflare (onclick etc) tho its not a very user friendly error

If I find more XSS vulns I'll post them here instead of making more threads if thats cool
 

Zed

Zedmin / Managing Director
Team CubeCraft
💙 Admin Team
Jul 11, 2015
248
2,922
268
Radcliffe, Manchester
twitter.com
This is just the bbcode attributes right?

I think this is intended behaviour (ie being able to control width) - Xenforo will strip out any disallowed attributes.

Bug is that you can cause statuses to overflow with this which isn't ideal.
 

Rifyy

Well-Known Member
Aug 19, 2019
95
334
104
This is just the bbcode attributes right?
I dont know whether this is possible with BB codes, last time I really used BB codes is ~10 years ago when this certainly wasnt a thing you could usually do with them. I used element inspect and edited richt text editor input which is why I titled it XSS

Quick test to see whether its possible on the current forum too, never tested it here
iu


Source image is 1500px wide

Edit: doesnt seem to work here
 

Zed

Zedmin / Managing Director
Team CubeCraft
💙 Admin Team
Jul 11, 2015
248
2,922
268
Radcliffe, Manchester
twitter.com
I dont know whether this is possible with BB codes, last time I really used BB codes is ~10 years ago when this certainly wasnt a thing you could usually do with them. I used element inspect and edited richt text editor input which is why I titled it XSS

Quick test to see whether its possible on the current forum too, never tested it here
iu


Source image is 1500px wide

Edit: doesnt seem to work here
width / height are allowed editable elements in the new BB code so I think you're just mutating the values - any other adjustments won't come through. If you inspect the network traffic you should see that sanitised BB code is sent back to the server not HTML.
 

Rifyy

Well-Known Member
Aug 19, 2019
95
334
104
you should see that sanitised BB code is sent back to the server not HTML.
upload_2020-5-18_21-46-44.png

Sanitation doesn't seem to be working for me? Seeing the <p> text being sent to the server is what made me try messing around with image tags to begin with
 
Members Online

Members online

Latest posts

Latest profile posts

Reesle wrote on __obektev__'s profile.
Welcome to the Official Cubecraft Forums! Hope you enjoy your time here :)
Reesle wrote on Otherworld's profile.
Cool banner!
LitDs have been about the normal, human-to-human relationships in the world, so there's a lot of ideas that I want to write, that are not so grand or lore-focused.

But I don't really want to write anymore.

I literally went through today with no motivation to do ANYTHING... help me.
This past week has seriously been the worst. Terrible things keep happening one after the other.
I have no motivation to write (as well as a bunch of things that I need to get done). However, I have this random plot idea of a new LitD. Two characters who are rivals in many cooking competitions throughout their lives but one of them is in love with the other.

1716070529301.png
Top Bottom