File tree Expand file tree Collapse file tree 2 files changed +5
-3
lines changed
lib/internal/Magento/Framework/Filter Expand file tree Collapse file tree 2 files changed +5
-3
lines changed Original file line number Diff line number Diff line change @@ -30,9 +30,9 @@ class MaliciousCode implements \Zend_Filter_Interface
3030 '/(ondblclick|onclick|onkeydown|onkeypress|onkeyup|onmousedown|onmousemove|onmouseout|onmouseover|onmouseup| ' .
3131 'onload|onunload|onerror)=[^<]*(?=\/*\>)/Uis ' ,
3232 //tags
33- '/<\/?\?? (script|meta|link|frame|iframe|object).*>/Uis ' ,
33+ '/<\/?(script|meta|link|frame|iframe|object).*>/Uis ' ,
3434 //scripts
35- '/<\/?\?? (php).*>/Uis ' ,
35+ '/<\?{1}\s*? (php|= ).*>/Uis ' ,
3636 //base64 usage
3737 '/src=[^<]*base64[^<]*(?=\/*\>)/Uis ' ,
3838 ];
Original file line number Diff line number Diff line change @@ -114,7 +114,9 @@ public function filterDataProvider()
114114 'alert(1); ' ,
115115 ],
116116 'Nested scripts ' => [
117- '<?php echo "test"?> ' ,
117+ '<?php echo "test" ?> ' ,
118+ '' ,
119+ '<?= "test" ?> ' ,
118120 '' ,
119121 ],
120122 ];
You can’t perform that action at this time.
0 commit comments