Quote:
Originally Posted by loaep
Well, it's non-persistent, so it's not 100% harmful, but if somebody were to construct a URL, and get a mod, or an admin to click on it, they could steal your cookies, use it as there own, and they would be logged in as a mod / admin.
There are also more things they could do, exploit 0days in the browser etc.
I would recommend you apply my fix 
|
Thank you for the explanation loaep, just wanted to gain some knowledge about what the risks were. I see you work in web security and it's good to see that you offer us vBulletin modification security checks.
Again thank you so much for that bit of knowledge!