Sec Bug->Doc #77059 [Opn]: strip_tags fails to properly remove tags with whitespaces

From: Date: Fri, 26 Oct 2018 08:14:58 +0000
Subject: Sec Bug->Doc #77059 [Opn]: strip_tags fails to properly remove tags with whitespaces
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-16101@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77059&edit=1 ID: 77059 Updated by: cmb@php.net Reported by: alex at buayacorp dot com Summary: strip_tags fails to properly remove tags with whitespaces Status: Open -Type: Security +Type: Documentation Problem -Package: *General Issues +Package: Strings related Operating System: debian wheezy PHP Version: Irrelevant Block user comment: N Private report: Y New Comment: > (Valid) HTML tags can't have whitespaces after the < character. That. Anyhow, strip_tags() is not the appropriate way to eliminate XSS vulnerabilites[1]. This should be documented in the manual. [1] <http://news.php.net/php.internals/102462> Previous Comments: ------------------------------------------------------------------------ [2018-10-25 19:45:36] alex at buayacorp dot com It looks like this might be an invalid issue after all. (Valid) HTML tags can't have whitespaces after the < character. Although it's somewhat interesting that FILTER_SANITIZE_STRING is a little bit more stricter. There was another code in play in the original PHP application I was looking at that was fixing the formatting of the resulting string after the strip_tags call. Please feel free to close this ticket as invalid, and sorry for the false positive. ------------------------------------------------------------------------ [2018-10-25 13:33:08] alex at buayacorp dot com filter_var( ..., FILTER_SANITIZE_STRING ); seems to call the underlying php_strip_tags_ex function with an appropriate allow_tag_spaces value https://github.com/php/php-src/blob/db47e35373513705b84b7391ed25e9854308eef2/ext/filter/sanitizing_filters.c#L212 ------------------------------------------------------------------------ [2018-10-25 13:15:46] alex at buayacorp dot com Description: ------------ Since PHP 4.3.2 release ([1], [2]), strip_tags seems to skip (until the next < character) whatever comes next if the sequence < (<+whitespace) is found. This seems somewhat problematic for some PHP applications that rely on this function as a way to remove unwanted html tags and which might also lead to XSS issues. If there's no intention to fix this, I guess a security warning note should likely be used in the documentation page. [1] https://3v4l.org/lNrL4 [2] https://github.com/php/php-src/commit/d9afe5c129ac7ff55f150f8263e71b2d5d4c5544 Test script: --------------- <?php var_dump(strip_tags('< img src=x onerror=alert(1)>hola< script >alert(1)')); Expected result: ---------------- string(12) "holaalert(1)" Actual result: -------------- string(51) "< img src=x onerror=alert(1)>hola< script >alert(1)" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77059&edit=1

« previous php.doc.bugs (#16101) next »