Using the most recent version of vBShop Lite available here in the thread, I have encountered as exploit which could be easily misused for next-to-malicious purposes...
Input fields for username styling allow anything to be input, and then sticks it directly into a <span style=""> tag. This allows for arbitrary code to be added in at the consumer's whim. I've applied a hotfix on my forum but would appreciate if an official update were made to fix this issue.
Kybyrian
|