PluginProbe
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder / 6.2.15
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder v6.2.15
6.2.15 6.2.14 6.2.13 6.2.12 6.2.10 6.2.11 6.2.9 6.2.8 6.2.7 6.2.6 6.2.5 6.2.4 6.2.3 6.2.2 3.6.22 3.6.31 3.6.40 3.6.41 3.6.42 3.6.50 3.6.51 3.6.60 3.6.61 3.6.62 3.6.64 All 197 releases
← All changes | app/Modules/MCP/Support/MCPHelper.php +11 -5 6.2.13 → 6.2.15 View file →
@@ -78,15 +78,21 @@
78 78 if (!apply_filters('fluentform/mcp_wrap_untrusted', true)) {
79 79 return $value;
80 80 }
81 81
82 - // Neutralize a submitter-supplied marker so the fence cannot be closed
83 - // from inside it (the classic delimiter-escape).
84 - $value = str_replace(
85 - [self::UNTRUSTED_OPEN, self::UNTRUSTED_CLOSE],
86 - ['(untrusted_user_input)', '(/untrusted_user_input)'],
82 + // Neutralize a submitter-supplied marker so the fence cannot be closed from
83 + // inside it. Loose match on purpose: the reader is a model, not strcmp.
84 + $neutralised = preg_replace_callback(
85 + '/\[\[[\s\p{Z}\p{Cf}]*(\/?)[\s\p{Z}\p{Cf}]*UNTRUSTED[^A-Za-z]*USER[^A-Za-z]*INPUT[\s\p{Z}\p{Cf}]*\]\]/iu',
86 + function ($m) {
87 + return '(' . ('' !== $m[1] ? '/' : '') . 'untrusted_user_input)';
88 + },
87 89 $value
88 90 );
91 +
92 + // /u returns null on invalid UTF-8: blunt the brackets rather than return a
93 + // value whose markers were never inspected.
94 + $value = null !== $neutralised ? $neutralised : str_replace('[[', '(', $value);
89 95
90 96 return self::UNTRUSTED_OPEN . $value . self::UNTRUSTED_CLOSE;
91 97 }
92 98