Originally Posted by Philipp
I hate to say it, but the current fix is insufficient and only changes the attack vector. It is still simple to redirect to a third-party site by including the website domain somewhere in the curl parameter.

Example: https://www.ubbcentral.com/forums/ubbthreads.php?ubb=changeprefs&what=style&value=1&curl=https://ubbdev.com/www.ubbcentral.com/

I am certain that the spammers will figure it out sooner or later. Personally, I would remove the entire "//domain.tld/ubbthreads.php/" part from the curl parameter.

Wow I tested this and it takes you direct to the third party, maybe something to bite into for the developers
Quote
https://www.ubbcentral.com/forums/ubbthreads.php?ubb=changeprefs&what=style&value=1&curl=https://ubbdev.com/faq/index.html/www.ubbcentral.com/

Here is the link in action

Last edited by Morgan; 11/25/2023 6:02 AM.

Morgan Johansson
BritBike Forum
https://www.britbike.com/forums/ubbthreads.php