[php-src] Issue #9663: add preg_quote_replacement() function

From: Date: Mon, 03 Oct 2022 13:05:42 +0000
Subject: [php-src] Issue #9663: add preg_quote_replacement() function
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242516@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/9663 Author: tomasfejfar ### Description ```php $pattern = '/[[name]]/'; $template = 'My name is [[name]]'; preg_replace($pattern, $_POST['name'], $template); ``` This is prone to injection of any match from the pattern if user supplies for example Tomas$1Fejfar. There is a preg_quote function that can be used to escape special chars in template. There should be same function that would escape the replacement. ``` preg_quote_replacement($_POST['name']); // Tomas\$1Fejfar ``` IMHO it is enough to escape backslash and dollars with backslash, but I am not sure. Currently the replacement must be escaped using userland function that makes it prone to mistakes.

« previous php.bugs (#242516) next »