Quote:
Originally Posted by fmckinnon
Hey, yeah - well if I enable HTML in the forum permissions, it parses fine ... but I was advised a few pages back that it wasn't really safe to have HTML enabled on my forums. (I see even here vbulletin.org, the HTML code is Off)
Are you talking about doing this somewhere other than forum permissions? For the life of me, I cannot find anywhere to give a usergroup permissions to post HTML in posts ... only in signatures (in User Group Settings)
I am very grateful for your help - trying to get this thing fixed tonight!
|
Oh sorry, I am using this mod for that, I missed it:
https://vborg.vbsupport.ru/showthread.php?t=96926
According to
RS_Jelle, as said
here.
Quote:
When HTML is allowed, you can post malicious code. Like iframes (which can contain virusses) and JavaScript (which can be used to obtain admin passwords).
So you create a huge XSS security leak. Only allow it if you really trust all people in that usergroup.
|
So this mod is what you should use. Works on the latest version too.