I just realized this when I started viewing the forum as a guest. This hack is written so that if the logged in user doesn't have permission then they can't VIEW those BB-codes parsed. However, they can still include them in posts themselves, and users who do have permission to use them, will then see the parsed code posted by the disallowed users.
I see this as a big security risk depending on the BB-Code in question.
I developed a fix for this, so that vBulletin standard BB-Codes also work correctly. Will post later tonight, I have to run right now.
|