Sec Bug->Doc #77059 [Opn]: strip_tags fails to properly remove tags with whitespaces
| From: | cmb@php.net | Date: | Fri, 26 Oct 2018 08:14:58 +0000 |
| Subject: | Sec Bug->Doc #77059 [Opn]: strip_tags fails to properly remove tags with whitespaces | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-16101@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77059&edit=1
ID: 77059
Updated by: cmb@php.net
Reported by: alex at buayacorp dot com
Summary: strip_tags fails to properly remove tags with
whitespaces
Status: Open
-Type: Security
+Type: Documentation Problem
-Package: *General Issues
+Package: Strings related
Operating System: debian wheezy
PHP Version: Irrelevant
Block user comment: N
Private report: Y
New Comment:
> (Valid) HTML tags can't have whitespaces after the < character.
That.
Anyhow, strip_tags() is not the appropriate way to eliminate XSS
vulnerabilites[1]. This should be documented in the manual.
[1] <http://news.php.net/php.internals/102462>
Previous Comments:
------------------------------------------------------------------------
[2018-10-25 19:45:36] alex at buayacorp dot com
It looks like this might be an invalid issue after all. (Valid) HTML tags can't have
whitespaces after the < character. Although it's somewhat interesting that
FILTER_SANITIZE_STRING is a little bit more stricter.
There was another code in play in the original PHP application I was looking at that was fixing the
formatting of the resulting string after the strip_tags call. Please feel free to close this ticket
as invalid, and sorry for the false positive.
------------------------------------------------------------------------
[2018-10-25 13:33:08] alex at buayacorp dot com
filter_var( ..., FILTER_SANITIZE_STRING ); seems to call the underlying
php_strip_tags_ex function with an appropriate allow_tag_spaces value https://github.com/php/php-src/blob/db47e35373513705b84b7391ed25e9854308eef2/ext/filter/sanitizing_filters.c#L212
------------------------------------------------------------------------
[2018-10-25 13:15:46] alex at buayacorp dot com
Description:
------------
Since PHP 4.3.2 release ([1], [2]), strip_tags seems to skip (until the next < character)
whatever comes next if the sequence < (<+whitespace) is found. This seems
somewhat problematic for some PHP applications that rely on this function as a way to remove
unwanted html tags and which might also lead to XSS issues.
If there's no intention to fix this, I guess a security warning note should likely be used in
the documentation page.
[1] https://3v4l.org/lNrL4
[2] https://github.com/php/php-src/commit/d9afe5c129ac7ff55f150f8263e71b2d5d4c5544
Test script:
---------------
<?php
var_dump(strip_tags('< img src=x onerror=alert(1)>hola< script >alert(1)'));
Expected result:
----------------
string(12) "holaalert(1)"
Actual result:
--------------
string(51) "< img src=x onerror=alert(1)>hola< script >alert(1)"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77059&edit=1