RSS Feed/News css url signing does not protect all arguments

Status
Not open for further replies.

ENXF NET

Administrator
Staff member
Administrator
Moderator
+Lifetime VIP+
S.V.I.P.S Member
S.V.I.P Member
V.I.P Member
Collaborate
Registered
Joined
Nov 13, 2018
Messages
27,420
Points
823

Reputation:

XF url signs the autogenerated css.php links, however only covers the css argument and not the language/style/last modified arguments. It is also optional, so it can be completely trimmed off.

If url signing is going to be used it should cover all the style related arguments, and likely not be optional in non-debug mode.

Continue reading...
 
Status
Not open for further replies.
Top