Sec Bug->Bug #78814 [Opn]: strip_tags allows / in tag name, allowing whitelist bypass in browsers

From: Date: Sun, 17 Nov 2019 13:18:25 +0000
Subject: Sec Bug->Bug #78814 [Opn]: strip_tags allows / in tag name, allowing whitelist bypass in browsers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223758@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78814&edit=1 ID: 78814 Updated by: cmb@php.net Reported by: talkemade at computest dot nl Summary: strip_tags allows / in tag name, allowing whitelist bypass in browsers Status: Open -Type: Security +Type: Bug Package: Strings related Operating System: all PHP Version: 7.3.11 Block user comment: N Private report: Y New Comment: Okay, lets consult the docs[1]: | This function should not be used to try to prevent XSS attacks. So this is clearly not a security issue. I agree, though, that the reported behavior is erroneous, but would expect the following output b</strong> [1] <https://www.php.net/strip_tags> Previous Comments: ------------------------------------------------------------------------ [2019-11-14 14:59:16] cmb@php.net > If the whitelist is important for security […] Then the program makes a wrong assumption. ------------------------------------------------------------------------ [2019-11-14 12:16:52] talkemade at computest dot nl Description: ------------ When strip_tags is used with a whitelist of tags, php allows slashes ("/") that occur inside the name of a whitelisted tag and copies them to the result. For example, if <strong> is whitelisted, then a tag <s/trong> is also kept. The browsers Chrome, Firefox and Safari, however, interpret this syntax as <s trong=""> (in HTML this would result in a strikethrough element with an unknown attribute). This means that it's possible to use any tag which is a prefix of a tag that is whitelisted. If the whitelist is important for security then this can allow the introduction of non-whitelisted tags. Test script: --------------- <?php echo strip_tags("<s/trong>b</strong>", "<strong>"); Expected result: ---------------- b Actual result: -------------- <s/trong>b</strong> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78814&edit=1

« previous php.bugs (#223758) next »