\XF\Util\Color::isValidColor() produces a positive match for RGB values without commas, can break CSS

  • Thread starter Thread starter apathy
  • Start date Start date

apathy

Guest
Member
The regex used in this function is capable of producing a positive match when an RGB value without commas is entered - regex101 example

This can cause problems when creating Reactions for instance, if a comma-less RGB value is specified for the reaction text color, the CSS can break like in the attached screenshot.

Usually this wouldn't be a huge problem since I imagine most admins are using the color picker (which correctly produces commas), however some of my addons and I...

Read more

Continue reading...
 
Top