Description of the problem
When a member uploads an SVG and they must pass the do_xss_clean check, the original data will not be the same as the clean data (system/ee/legacy/libraries/Upload.php:869), because as part of the clean _remove_evil_attributes is called, this converts a valid opening tag from
<svg xmlns="http://www.w3.org/2000/svg"> to <svg>
this causes the check to fail as the return value is no longer equal
How To Reproduce
Steps to reproduce the behavior:
Upload an SVG as a non super admin, xss_check() must return true.
Error Messages
Gives a generic "The file could not be written to disk." message
Environment Details:
- Version: 7.5.26
- PHP Version 8.4
- MySQL Version 8.4.9
- OS: Linux
- Web Server: nginx
Possible Solution
When dealing with a file_type of 'image/svg', it may be possible to put the stripped xmlns back in, something like:
$hadXmlns = (bool) preg_match('/<svg[^>]+xmlns=/i', $data);
// do the sanitisation
if (strpos($this->file_type, 'image/svg') === 0 && $hadXmlns && strpos($data, 'xmlns=') === false) {
$data = preg_replace('/<svg/i', '<svg xmlns="http://www.w3.org/2000/svg"', $data, 1);
}
Not the prettiest but something along theses lines would be nice.
Description of the problem
When a member uploads an SVG and they must pass the do_xss_clean check, the original data will not be the same as the clean data (system/ee/legacy/libraries/Upload.php:869), because as part of the clean
_remove_evil_attributesis called, this converts a valid opening tag from<svg xmlns="http://www.w3.org/2000/svg">to<svg>this causes the check to fail as the return value is no longer equal
How To Reproduce
Steps to reproduce the behavior:
Upload an SVG as a non super admin, xss_check() must return true.
Error Messages
Gives a generic "The file could not be written to disk." message
Environment Details:
Possible Solution
When dealing with a file_type of 'image/svg', it may be possible to put the stripped xmlns back in, something like:
$hadXmlns = (bool) preg_match('/<svg[^>]+xmlns=/i', $data);// do the sanitisation
if (strpos($this->file_type, 'image/svg') === 0 && $hadXmlns && strpos($data, 'xmlns=') === false) {$data = preg_replace('/<svg/i', '<svg xmlns="http://www.w3.org/2000/svg"', $data, 1);
}
Not the prettiest but something along theses lines would be nice.