| @@ -1,8 +1,9 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | namespace TablePress\PhpOffice\PhpSpreadsheet\Shared; |
| 4 | 4 | |
| 5 | +use TablePress\Composer\Pcre\Preg; | |
| 5 | 6 | use TablePress\PhpOffice\PhpSpreadsheet\Exception; |
| 6 | 7 | use TablePress\PhpOffice\PhpSpreadsheet\Reader\Exception as ReaderException; |
| 7 | 8 | use ZipArchive; |
| 8 | 9 | |
| @@ -136,21 +137,24 @@ | ||
| 136 | 137 | return tempnam(self::sysGetTempDir(), 'phpspreadsheet'); |
| 137 | 138 | } |
| 138 | 139 | |
| 139 | 140 | /** |
| 140 | - * All filenames starting with protocol (e.g. phar://) are prohibited. | |
| 141 | + * Blocks phar:// and similar RCE-bearing wrappers. | |
| 141 | 142 | * Note that many protocols, including http and zip, will already |
| 142 | 143 | * return false for is_file. |
| 143 | 144 | * A whitelist of protocols may be added if needed in future. |
| 145 | + * data: is intentionally allowed (see #4823); callers needing strict | |
| 146 | + * on-disk-only semantics must validate $filename themselves. | |
| 144 | 147 | */ |
| 145 | 148 | public static function prohibitWrappers(string $filename): void |
| 146 | 149 | { |
| 147 | - $scheme = parse_url($filename, PHP_URL_SCHEME); | |
| 148 | - // strlen check > 1 to avoid issues with Windows absolute paths (e.g. C:\...), Windows quirks :) | |
| 149 | - // since no built-in or commonly registered PHP stream wrapper uses a single-character scheme, this should be ok, to my knowledge | |
| 150 | - if (is_string($scheme) && strlen($scheme) > 1) { | |
| 150 | + if ( | |
| 151 | + Preg::IsMatch('~^phar://~i', $filename) | |
| 152 | + || (Preg::isMatch('/^([\w.\s\x00-\x1f]+):/', $filename) && !Preg::isMatch('/^([\w.]+):/', $filename)) | |
| 153 | + || Preg::isMatch('~^[\w.]+://.*phar:~is', $filename) | |
| 154 | + ) { | |
| 151 | 155 | throw new Exception( |
| 152 | - "Stream wrappers are not permitted as file paths: {$filename}" | |
| 156 | + "Disallowed stream wrapper used for {$filename}" | |
| 153 | 157 | ); |
| 154 | 158 | } |
| 155 | 159 | } |
| 156 | 160 | |