Jump to content
HWBOT Community Forums

Customize Profile Button


Recommended Posts

Yes, seems to be gone, but I can't really tell if something is still applied, since the site uses the custom styles from my profile :D

Some of the styles are a little off, due to some upgrades during the years though.

The logo I had is gone.

PS: Actually the custom css is still applied, the background on my profile page uses black/grey shade rather than the default blue of the rest of the pages.

Edited by I.nfraR.ed
Link to comment
Share on other sites

Haha, so I now know what he tried to do, either by mistake, or intentionally exploiting css injection vulnerabilities :D

In fact I wanted to test it and report if something is wrong, but never actually got to it. Custom CSS without sanitizing it can be dangerous.

PS: I think it is possible to steal someones account using that kind of XSS attack, but haven't drilled much in the topic.

So..a good call, I would say.

Edited by I.nfraR.ed
  • Haha 1
Link to comment
Share on other sites

Good question.

IMO, any customization needs to be controlled with the appropriate interface for that.

I guess that feature will be back at some point, but not the free form css input.

If a "theme" customization is needed, then some sort of a theme editor has to be implemented.

Edited by I.nfraR.ed
  • Like 1
Link to comment
Share on other sites

  • 3 weeks later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Create New...