• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
    • Forum
    • Wiki
    • Support
      • Manage Subscriptions
      • FAQ
      • Support For
        • VaultWiki 4.x Series
        • VaultWiki.org Site
    • What's New?
    • Buy Now
    • Manual
    • 
    • Support
    • VaultWiki 4.x Series
    • Bug
    • html is parsed into summary

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    Issue: html is parsed into summary

    • Issue Tools
      • View Changes
    1. issueid=6185 March 14, 2021 10:24 AM
      Alfa1 Alfa1 is offline
      Distinguished Member
      html is parsed into summary

      If a page does not have a summary added then the start of the article is used. But if that content includes references then this will be used as raw html. If the content contains characters like & or ' etc then this will be used as HTML Ampersand Character Codes.
      Which negatively affects how meta description is displayed in search engine results.
    Issue Details
    Issue Number 6185
    Issue Type Bug
    Project VaultWiki 4.x Series
    Category Search Engine Optimization
    Status Won't Fix
    Priority 3 - Loss of Functionality
    Affected Version 4.1.1
    Fixed Version (none)
    Milestone (none)
    Software DependencyXenForo 1.x
    License TypePaid
    Users able to reproduce bug 0
    Users unable to reproduce bug 0
    Attachments 0
    Assigned Users (none)
    Tags (none)




    1. March 14, 2021 3:44 PM
      pegasus pegasus is offline
      VaultWiki Team
      Unfortunately this is the unfortunate side effect of fixing things after content was generated relying on buggy behavior. Most of this is in relation to the mitigation required to fully fix the VWE-2020-5454 escalation (January 2020) and VWE-2020-5727 injections (April 2020).

      First, there is no currently supported version where VaultWiki uses the start of the article as a summary. You have said this in multiple places, but it is not the case and it is misleading to other users.

      Some history: back when it did, the original fix for VWE-2020-5454 limited the ability to show parsed content intended for another specific user, by not parsing content (showing it as raw). The intent was to stop automatic summaries completely at that point but it did not make it into the patch for one reason or another (likely due to not having an alternate solution). After the patch, it still was possible to display restricted content generally due to not being able to parse it out anymore. When 4.1.x was released, automatically using article content to fill an empty summary was completely removed; there was now the ability to manually define summaries; this also fixed the regression from VaultWiki 3.x, which also had manual summaries.

      This means that many of your existing summaries are all there because they were existing content. Your existing content for certain articles happens to correspond with the beginning of those articles, due to prior behavior. We do not remove existing content, even if it was once possible to save content containing vulnerabilities. Ultimately it is your responsibility to determine if any particular entry warrants removal.

      Back when summaries were made from the start of articles, it was necessary to ensure that injections were not possible by inadventently including raw HTML tags in the summary. Prior to VWE-2020-5454, this was done by the act of parsing the start of the article, resulting in the summary content being saved with raw characters encoded. Once parsing was no longer done, VWE-2020-5727 had to be introduced, because on newer summaries, those raw tags could now make it into the output. Since there was no way really to tell the difference, summaries had to be encoded on display across the board. For pre-5454 summaries, this means they got unfortunately double-encoded (once whenever they were saved, and now when they are displayed).

      Once VaultWiki 4.1.x allowed users to set it manually, this further increased the need to encode raw tags on display, to avoid injections. So 5727 is important.

      ----

      TLDR; What you are basically asking is that we roll back the mitigation against one vulnerability (5727) because content that was generated by relying on an even earlier vulnerability (5454) does not render in a user-friendly way. We will not do this. If mitigation has caused some display issues, you should update the affected content. As far as I'm aware, there are no double-encoding issues regarding changes to summaries.
      Reply Reply  
    2. March 15, 2021 11:03 AM
      Alfa1 Alfa1 is offline
      Distinguished Member
      I will update all summaries manually anyway. I reported it in case it was still an issue affecting supported versions of VW. But as this is not the case its not an issue. Thank you for explaining.
      Reply Reply  
    + Reply

    Assigned Users
    Loading Please Wait
    Tags
    Loading Please Wait
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 10:45 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.