Skip to content

SVG upload should not fail xss clean over xmlns #5393

Description

@DONEILL-emp

Description of the problem
When a member uploads an SVG and they must pass the do_xss_clean check, the original data will not be the same as the clean data (system/ee/legacy/libraries/Upload.php:869), because as part of the clean _remove_evil_attributes is called, this converts a valid opening tag from

<svg xmlns="http://www.w3.org/2000/svg"> to <svg>

this causes the check to fail as the return value is no longer equal

How To Reproduce
Steps to reproduce the behavior:
Upload an SVG as a non super admin, xss_check() must return true.

Error Messages
Gives a generic "The file could not be written to disk." message

Environment Details:

  • Version: 7.5.26
  • PHP Version 8.4
  • MySQL Version 8.4.9
  • OS: Linux
  • Web Server: nginx

Possible Solution
When dealing with a file_type of 'image/svg', it may be possible to put the stripped xmlns back in, something like:

$hadXmlns = (bool) preg_match('/<svg[^>]+xmlns=/i', $data);

// do the sanitisation

if (strpos($this->file_type, 'image/svg') === 0 && $hadXmlns && strpos($data, 'xmlns=') === false) {
$data = preg_replace('/<svg/i', '<svg xmlns="http://www.w3.org/2000/svg"', $data, 1);
}

Not the prettiest but something along theses lines would be nice.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions