vgstation-coders / vgstation13

Butts
GNU General Public License v3.0
260 stars 541 forks source link

Href abuse leading to sending unsanitized text in message_admins #29491

Open Sakuya-Izayoi opened 3 years ago

Sakuya-Izayoi commented 3 years ago

Description of issue

Href abuse in player panel (requires admin rights) allows an unsanitized text to be sent to admins.

Specific information for locating

https://github.com/vgstation-coders/vgstation13/blob/51bc6e486c12ede6c62697a27da0250745f73a37/code/modules/admin/topic.dm#L688

I'm not a vgstation player, I just found this bug on the server I play and looked for the same issue on some codebases.

help-maint commented 3 years ago

Based

Kammerjunk commented 3 years ago

dangerously based

Eneocho commented 3 years ago

respectable autism