You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This website uses the latest version of valine, the comment cannot be loaded normally
受影响的Valine版本、操作系统,以及浏览器信息
Valine 1.4.14
OS:Windows/Linux/macOS
Browser: Chrome、Firefox、Safair
总的来说就是 如果有用户恶意修改 UA 评论的话,会直接把那个页面评论打瘫痪掉,我是在排查我的一篇 300 多个评论文章的时候发现的,把 leancloud 从里到外排查了一遍 才发现了这个 BUG,希望作者大大后面可以修复这个尴尬的问题
The text was updated successfully, but these errors were encountered:
sqlsec
changed the title
Found a fatal bug that can kill the comment system
a fatal bug that can kill the comment system(用户恶意修改 UA 评论 可影响正常评论加载)
Jun 16, 2021
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
如果您想报告错误,请提供以下信息 If you want to report a bug, please provide the following information:
可复现问题的步骤 The steps to reproduce.
The latest version of valine is 1.4.14,Let's first look at the effect of normal page loading comments:
When the commented user UA is incomplete,such as:
This will cause the entire comment system of the current page to be damaged and the comments cannot be loaded normally
可复现问题的网页地址
https://islu.cn/posts/38530.html
This website uses the latest version of valine, the comment cannot be loaded normally
受影响的Valine版本、操作系统,以及浏览器信息
总的来说就是 如果有用户恶意修改 UA 评论的话,会直接把那个页面评论打瘫痪掉,我是在排查我的一篇 300 多个评论文章的时候发现的,把 leancloud 从里到外排查了一遍 才发现了这个 BUG,希望作者大大后面可以修复这个尴尬的问题
The text was updated successfully, but these errors were encountered: