Bug #1731

Custom profile fields lenght is not validate

Added by Lukasz Tkacz over 2 years ago. Updated about 2 years ago.

Status:ClosedStart date:09/22/2011
Priority:NormalDue date:
Assignee:Tom Moore% Done:


Category:User Control Panel
Target version:1.6.7
Reproducibility:Always Database Type:MySQLi
Reported In MyBB Version:1.6.4 Database Version:
PHP Version: SQA assignments:Nathan Malcolm


custom profile fields length is not validate after send form. There is "maxlength" value in HTML code, but users can modify it.
I attach screen with modified field by firebug - it's no problem to send very long data and exceed the field range in database

custom_fields.png (67.1 KB) Lukasz Tkacz, 09/22/2011 06:50 am


#1 Updated by Will Pillar over 2 years ago

There doesn't appear to be any server-side validation of field lengths for custom profile fields. There should be.

#2 Updated by Tom Moore over 2 years ago

  • Status changed from New to Assigned
  • Assignee set to Tom Moore
  • Target version set to 1.6.6

#3 Updated by Tom Moore over 2 years ago

  • Status changed from Assigned to Resolved
  • % Done changed from 0 to 100

Applied in changeset r5675.

#4 Updated by Nathan Malcolm over 2 years ago

  • Status changed from Resolved to Closed
  • SQA assignments set to Nathan Malcolm

#5 Updated by Tom Moore about 2 years ago

  • Target version changed from 1.6.6 to 1.6.7

Also available in: Atom PDF