Bug #74371 [Com]: strip_tags altering attributes

From: Date: Mon, 07 Sep 2020 12:28:27 +0000
Subject: Bug #74371 [Com]: strip_tags altering attributes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-228927@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74371&edit=1

 ID:                 74371
 Comment by:         ad at asd dot com
 Reported by:        php-bugs at aspectis dot net
 Summary:            strip_tags altering attributes
 Status:             Verified
 Type:               Bug
 Package:            *General Issues
 PHP Version:        7.1.3
 Block user comment: N
 Private report:     N

 New Comment:

"><img src=1 href=1 onerror="javascript:alert(1)"></img>


Previous Comments:
------------------------------------------------------------------------
[2017-08-12 01:04:34] ajf@php.net

Looks like a real bug to me.

One solution might be to round-trip it through an HTML parser (say, DOMDocument) first.

------------------------------------------------------------------------
[2017-04-04 20:28:44] spam2 at rhsoft dot net

you don't get it - the whole purpose of strip_tags is to get rid auf dangerous chars like <
and >

------------------------------------------------------------------------
[2017-04-04 19:56:53] php-bugs at aspectis dot net

This may be true for XHTML, but in HTML 4 and 5 "<" and ">" are perfectly
valid characters for attribute values.

------------------------------------------------------------------------
[2017-04-04 19:45:39] spam2 at rhsoft dot net

your source code is just plain wrong when it contains < or > because these chars needs to be
encoded as entities and the whole purpose of strip_tags() is to FIX such issues to PREVENT that your
tag itself get closed by unencoded value

------------------------------------------------------------------------
[2017-04-04 18:41:26] php-bugs at aspectis dot net

Description:
------------
The manual claims that strip_tags "does not modify any attributes on the tags that you
allow" (http://www.php.net/function.strip-tags), which unfortunately isn't quite true:

The characters "<" and ">" get stripped from all attribute values.

All versions at least from 5.4 seem to be affected.

Test script:
---------------
echo strip_tags('<img src="example.jpg" alt=":> :<">',
'<img>');


Expected result:
----------------
<img src="example.jpg" alt=":> :<">

Actual result:
--------------
<img src="example.jpg" alt=": :">


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74371&edit=1


Thread (7 messages)

« previous php.bugs (#228927) next »