Minecraft PC IP: play.cubecraft.net

Rifyy

Well-Known Member
Aug 19, 2019
95
334
104
If you embed an image you can edit the style attribute and set the width to whatever you like. there is still a wrapper element for the displayed image so you cant make it bigger than default but you can make it smaller

upload_2020-5-16_23-46-53.png


I inserted the image element manually with element inspect too, might make a difference

I doubt this is the only XSS vulnerability, all events seem to be blocked by cloudflare (onclick etc) tho its not a very user friendly error

If I find more XSS vulns I'll post them here instead of making more threads if thats cool
 

Zed

Zedmin / Managing Director
Team CubeCraft
💙 Admin Team
Jul 11, 2015
248
2,922
268
Radcliffe, Manchester
twitter.com
This is just the bbcode attributes right?

I think this is intended behaviour (ie being able to control width) - Xenforo will strip out any disallowed attributes.

Bug is that you can cause statuses to overflow with this which isn't ideal.
 

Rifyy

Well-Known Member
Aug 19, 2019
95
334
104
This is just the bbcode attributes right?
I dont know whether this is possible with BB codes, last time I really used BB codes is ~10 years ago when this certainly wasnt a thing you could usually do with them. I used element inspect and edited richt text editor input which is why I titled it XSS

Quick test to see whether its possible on the current forum too, never tested it here
iu


Source image is 1500px wide

Edit: doesnt seem to work here
 

Zed

Zedmin / Managing Director
Team CubeCraft
💙 Admin Team
Jul 11, 2015
248
2,922
268
Radcliffe, Manchester
twitter.com
I dont know whether this is possible with BB codes, last time I really used BB codes is ~10 years ago when this certainly wasnt a thing you could usually do with them. I used element inspect and edited richt text editor input which is why I titled it XSS

Quick test to see whether its possible on the current forum too, never tested it here
iu


Source image is 1500px wide

Edit: doesnt seem to work here
width / height are allowed editable elements in the new BB code so I think you're just mutating the values - any other adjustments won't come through. If you inspect the network traffic you should see that sanitised BB code is sent back to the server not HTML.
 

Rifyy

Well-Known Member
Aug 19, 2019
95
334
104
you should see that sanitised BB code is sent back to the server not HTML.
upload_2020-5-18_21-46-44.png

Sanitation doesn't seem to be working for me? Seeing the <p> text being sent to the server is what made me try messing around with image tags to begin with
 
Members Online

Members online

Latest posts

Latest profile posts

Matriox wrote on xEefster's profile.
Happy birthday eef
Basketman wrote on Eli's profile.
Happy Birthday Forums Guru (ELI) Enjoy your day and I hope these small messages here make your day! 🥳
JokeKaedee wrote on Eli's profile.
Happy birthday, Eli! I hope that today will be filled with joy and happiness only!!
Enjoy your day 🐉 :heart:
Reesle wrote on RatedManMp46's profile.
Happy Birthday! 🥳
Matriox wrote on Eli's profile.
HI

ITS YOUR BIRTHDAY

happy birthday Eli

1714947914949.png


1714948030659.png


here, take some beans:
1714948068073.png
Top Bottom