Attack
Forum Üyesi
- Katılım
- 4 Şub 2023
- Mesajlar
- 2,618
- Puanları
- 0
When a search has a valid search handler, and c.type or c.content are used , XenForo does not validate that they are covered by getSearchableContentTypes.
This allows constructing a query which likely side-steps getTypePermissionConstraints for those types.
For example:
This will lack the normal node visibility checks that a post/thread search would have.
The problem is in prepareSearchQuery which handles...
This allows constructing a query which likely side-steps getTypePermissionConstraints for those types.
For example:
Misafirler için gizlenen link, görmek için
Giriş yap veya üye ol.
.This will lack the normal node visibility checks that a post/thread search would have.
The problem is in prepareSearchQuery which handles...
Misafirler için gizlenen link, görmek için
Giriş yap veya üye ol.