Bug #78814 [Opn->Ver]: strip_tags allows / in tag name, allowing whitelist bypass in browsers
| From: | cmb@php.net | Date: | Sun, 17 Nov 2019 13:29:43 +0000 |
| Subject: | Bug #78814 [Opn->Ver]: strip_tags allows / in tag name, allowing whitelist bypass in browsers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223760@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78814&edit=1
ID: 78814
Updated by: cmb@php.net
Reported by: talkemade at computest dot nl
Summary: strip_tags allows / in tag name, allowing whitelist
bypass in browsers
-Status: Open
+Status: Verified
Type: Bug
Package: Strings related
Operating System: all
PHP Version: 7.3.11
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2019-11-17 13:23:45] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #78814: strip_tags allows / in tag name => whitelist bypass
On GitHub: https://github.com/php/php-src/pull/4923
Patch: https://github.com/php/php-src/pull/4923.patch
------------------------------------------------------------------------
[2019-11-17 13:18:25] cmb@php.net
Okay, lets consult the docs[1]:
| This function should not be used to try to prevent XSS attacks.
So this is clearly not a security issue. I agree, though, that
the reported behavior is erroneous, but would expect the following
output
b</strong>
[1] <https://www.php.net/strip_tags>
------------------------------------------------------------------------
[2019-11-14 14:59:16] cmb@php.net
> If the whitelist is important for security [â¦]
Then the program makes a wrong assumption.
------------------------------------------------------------------------
[2019-11-14 12:16:52] talkemade at computest dot nl
Description:
------------
When strip_tags is used with a whitelist of tags, php allows slashes ("/") that occur
inside the name of a whitelisted tag and copies them to the result.
For example, if <strong> is whitelisted, then a tag <s/trong> is also kept.
The browsers Chrome, Firefox and Safari, however, interpret this syntax as <s
trong=""> (in HTML this would result in a strikethrough element with an unknown
attribute). This means that it's possible to use any tag which is a prefix of a tag that is
whitelisted. If the whitelist is important for security then this can allow the introduction of
non-whitelisted tags.
Test script:
---------------
<?php
echo strip_tags("<s/trong>b</strong>", "<strong>");
Expected result:
----------------
b
Actual result:
--------------
<s/trong>b</strong>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78814&edit=1