Bug #78814 [Opn->Ver]: strip_tags allows / in tag name, allowing whitelist bypass in browsers

From: Date: Sun, 17 Nov 2019 13:29:43 +0000
Subject: Bug #78814 [Opn->Ver]: strip_tags allows / in tag name, allowing whitelist bypass in browsers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223760@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78814&edit=1 ID: 78814 Updated by: cmb@php.net Reported by: talkemade at computest dot nl Summary: strip_tags allows / in tag name, allowing whitelist bypass in browsers -Status: Open +Status: Verified Type: Bug Package: Strings related Operating System: all PHP Version: 7.3.11 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2019-11-17 13:23:45] cmb@php.net The following pull request has been associated: Patch Name: Fix #78814: strip_tags allows / in tag name => whitelist bypass On GitHub: https://github.com/php/php-src/pull/4923 Patch: https://github.com/php/php-src/pull/4923.patch ------------------------------------------------------------------------ [2019-11-17 13:18:25] cmb@php.net Okay, lets consult the docs[1]: | This function should not be used to try to prevent XSS attacks. So this is clearly not a security issue. I agree, though, that the reported behavior is erroneous, but would expect the following output b</strong> [1] <https://www.php.net/strip_tags> ------------------------------------------------------------------------ [2019-11-14 14:59:16] cmb@php.net > If the whitelist is important for security […] Then the program makes a wrong assumption. ------------------------------------------------------------------------ [2019-11-14 12:16:52] talkemade at computest dot nl Description: ------------ When strip_tags is used with a whitelist of tags, php allows slashes ("/") that occur inside the name of a whitelisted tag and copies them to the result. For example, if <strong> is whitelisted, then a tag <s/trong> is also kept. The browsers Chrome, Firefox and Safari, however, interpret this syntax as <s trong=""> (in HTML this would result in a strikethrough element with an unknown attribute). This means that it's possible to use any tag which is a prefix of a tag that is whitelisted. If the whitelist is important for security then this can allow the introduction of non-whitelisted tags. Test script: --------------- <?php echo strip_tags("<s/trong>b</strong>", "<strong>"); Expected result: ---------------- b Actual result: -------------- <s/trong>b</strong> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78814&edit=1

« previous php.bugs (#223760) next »