Bug #78814 [Ver->Csd]: strip_tags allows / in tag name, allowing whitelist bypass in browsers

From: Date: Mon, 02 Dec 2019 10:40:36 +0000
Subject: Bug #78814 [Ver->Csd]: strip_tags allows / in tag name, allowing whitelist bypass in browsers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224004@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78814&edit=1 ID: 78814 Updated by: cmb@php.net Reported by: talkemade at computest dot nl Summary: strip_tags allows / in tag name, allowing whitelist bypass in browsers -Status: Verified +Status: Closed Type: Bug Package: Strings related Operating System: all PHP Version: 7.3.11 Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=600f1f898f9771d13880255e74ea1c10590f5fd5 Log: Fix #78814: strip_tags allows / in tag name =&gt; whitelist bypass Previous Comments: ------------------------------------------------------------------------ [2019-11-17 13:23:45] cmb@php.net The following pull request has been associated: Patch Name: Fix #78814: strip_tags allows / in tag name => whitelist bypass On GitHub: https://github.com/php/php-src/pull/4923 Patch: https://github.com/php/php-src/pull/4923.patch ------------------------------------------------------------------------ [2019-11-17 13:18:25] cmb@php.net Okay, lets consult the docs[1]: | This function should not be used to try to prevent XSS attacks. So this is clearly not a security issue. I agree, though, that the reported behavior is erroneous, but would expect the following output b</strong> [1] <https://www.php.net/strip_tags> ------------------------------------------------------------------------ [2019-11-14 14:59:16] cmb@php.net > If the whitelist is important for security […] Then the program makes a wrong assumption. ------------------------------------------------------------------------ [2019-11-14 12:16:52] talkemade at computest dot nl Description: ------------ When strip_tags is used with a whitelist of tags, php allows slashes ("/") that occur inside the name of a whitelisted tag and copies them to the result. For example, if <strong> is whitelisted, then a tag <s/trong> is also kept. The browsers Chrome, Firefox and Safari, however, interpret this syntax as <s trong=""> (in HTML this would result in a strikethrough element with an unknown attribute). This means that it's possible to use any tag which is a prefix of a tag that is whitelisted. If the whitelist is important for security then this can allow the introduction of non-whitelisted tags. Test script: --------------- <?php echo strip_tags("<s/trong>b</strong>", "<strong>"); Expected result: ---------------- b Actual result: -------------- <s/trong>b</strong> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78814&edit=1

« previous php.bugs (#224004) next »