| @@ -78,15 +78,21 @@ | ||
| 78 | 78 | if (!apply_filters('fluentform/mcp_wrap_untrusted', true)) { |
| 79 | 79 | return $value; |
| 80 | 80 | } |
| 81 | 81 | |
| 82 | - // Neutralize a submitter-supplied marker so the fence cannot be closed | |
| 83 | - // from inside it (the classic delimiter-escape). | |
| 84 | - $value = str_replace( | |
| 85 | - [self::UNTRUSTED_OPEN, self::UNTRUSTED_CLOSE], | |
| 86 | - ['(untrusted_user_input)', '(/untrusted_user_input)'], | |
| 82 | + // Neutralize a submitter-supplied marker so the fence cannot be closed from | |
| 83 | + // inside it. Loose match on purpose: the reader is a model, not strcmp. | |
| 84 | + $neutralised = preg_replace_callback( | |
| 85 | + '/\[\[[\s\p{Z}\p{Cf}]*(\/?)[\s\p{Z}\p{Cf}]*UNTRUSTED[^A-Za-z]*USER[^A-Za-z]*INPUT[\s\p{Z}\p{Cf}]*\]\]/iu', | |
| 86 | + function ($m) { | |
| 87 | + return '(' . ('' !== $m[1] ? '/' : '') . 'untrusted_user_input)'; | |
| 88 | + }, | |
| 87 | 89 | $value |
| 88 | 90 | ); |
| 91 | + | |
| 92 | + // /u returns null on invalid UTF-8: blunt the brackets rather than return a | |
| 93 | + // value whose markers were never inspected. | |
| 94 | + $value = null !== $neutralised ? $neutralised : str_replace('[[', '(', $value); | |
| 89 | 95 | |
| 90 | 96 | return self::UNTRUSTED_OPEN . $value . self::UNTRUSTED_CLOSE; |
| 91 | 97 | } |
| 92 | 98 | |