← All changes
|
app/Services/FormBuilder/EditorShortcodeParser.php
+29
-2
6.2.14
→
6.2.15
View file →
| @@ -113,9 +113,9 @@ | ||
| 113 | 113 | if (false !== strpos($handler, 'cookie.')) { |
| 114 | 114 | $scookieProperty = substr($handler, strlen('cookie.')); |
| 115 | 115 | $cookieValue = array_key_exists($scookieProperty, $_COOKIE) ? sanitize_text_field(wp_unslash($_COOKIE[$scookieProperty])) : ''; |
| 116 | 116 | |
| 117 | - return esc_attr($cookieValue); | |
| 117 | + return static::escapeReflectedValue($cookieValue); | |
| 118 | 118 | } |
| 119 | 119 | |
| 120 | 120 | if (false !== strpos($handler, 'dynamic.')) { |
| 121 | 121 | $dynamicKey = substr($handler, strlen('dynamic.')); |
| @@ -175,9 +175,36 @@ | ||
| 175 | 175 | if (null === $value || '' === $value) { |
| 176 | 176 | return ''; |
| 177 | 177 | } |
| 178 | 178 | |
| 179 | - return esc_attr(Helper::flattenRequestValue($value)); | |
| 179 | + return static::escapeReflectedValue(Helper::flattenRequestValue($value)); | |
| 180 | + } | |
| 181 | + | |
| 182 | + /** | |
| 183 | + * Escape a visitor-supplied value ({get.x}, {cookie.x}) for the assembled form HTML. | |
| 184 | + * | |
| 185 | + * Smartcodes are substituted after Custom HTML was sanitized, so the value can land in | |
| 186 | + * any attribute, including an iframe src or anchor href. esc_attr() leaves a javascript: | |
| 187 | + * scheme intact and keeps existing entities (?p=java	script:...), so encode every | |
| 188 | + * ampersand and drop values that would resolve to a script-capable URL. | |
| 189 | + * | |
| 190 | + * @param string $value | |
| 191 | + * | |
| 192 | + * @return string | |
| 193 | + */ | |
| 194 | + public static function escapeReflectedValue($value) | |
| 195 | + { | |
| 196 | + $value = wp_check_invalid_utf8((string) $value); | |
| 197 | + | |
| 198 | + // Browsers strip control chars and whitespace from URLs before reading the scheme. | |
| 199 | + $scheme = strtolower(preg_replace('/[\x00-\x20]+/', '', $value)); | |
| 200 | + | |
| 201 | + if (preg_match('/^(javascript|vbscript|data):/', $scheme)) { | |
| 202 | + return ''; | |
| 203 | + } | |
| 204 | + | |
| 205 | + // Encode braces too, so the value cannot plant a smartcode for a later replacement pass. | |
| 206 | + return str_replace(['{', '}'], ['{', '}'], htmlspecialchars($value, ENT_QUOTES, 'UTF-8', true)); | |
| 180 | 207 | } |
| 181 | 208 | |
| 182 | 209 | /** |
| 183 | 210 | * Parse the curly braced shortcode into array |