File tree Expand file tree Collapse file tree 2 files changed +2
-1
lines changed
lib/internal/Magento/Framework/Filter Expand file tree Collapse file tree 2 files changed +2
-1
lines changed Original file line number Diff line number Diff line change @@ -30,7 +30,7 @@ class MaliciousCode implements \Zend_Filter_Interface
3030 '/(ondblclick|onclick|onkeydown|onkeypress|onkeyup|onmousedown|onmousemove|onmouseout|onmouseover|onmouseup| ' .
3131 'onload|onunload|onerror)=[^<]*(?=\/*\>)/Uis ' ,
3232 //tags
33- '/<\/?(script|meta|link|frame|iframe|object).*>/Uis ' ,
33+ '/<\/?\?? (script|meta|link|frame|iframe|object|php ).*>/Uis ' ,
3434 //base64 usage
3535 '/src=[^<]*base64[^<]*(?=\/*\>)/Uis ' ,
3636 ];
Original file line number Diff line number Diff line change @@ -112,6 +112,7 @@ public function filterDataProvider()
112112 'Nested malicious tags ' => [
113113 '<scri<script>pt>alert(1);</scri<script>pt> ' ,
114114 'alert(1); ' ,
115+ '<?php echo "test"?> ' ,
115116 ]
116117 ];
117118 }
You can’t perform that action at this time.
0 commit comments