PluginProbe
TablePress – Tables in WordPress made easy / 3.4
TablePress – Tables in WordPress made easy v3.4
3.4 3.3.4 3.3.3 3.3.2 3.3.1 trunk 1.12 1.14 1.9.2 2.0.4 2.1.7 2.1.8 2.2 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.3 2.3.1 2.3.2 2.4 2.4.1 2.4.2 2.4.3 All 45 releases
← All changes | libraries/vendor/PhpSpreadsheet/Shared/File.php +10 -6 3.3.1 → 3.4 View file →
@@ -1,8 +1,9 @@
1 1 <?php
2 2
3 3 namespace TablePress\PhpOffice\PhpSpreadsheet\Shared;
4 4
5 +use TablePress\Composer\Pcre\Preg;
5 6 use TablePress\PhpOffice\PhpSpreadsheet\Exception;
6 7 use TablePress\PhpOffice\PhpSpreadsheet\Reader\Exception as ReaderException;
7 8 use ZipArchive;
8 9
@@ -136,21 +137,24 @@
136 137 return tempnam(self::sysGetTempDir(), 'phpspreadsheet');
137 138 }
138 139
139 140 /**
140 - * All filenames starting with protocol (e.g. phar://) are prohibited.
141 + * Blocks phar:// and similar RCE-bearing wrappers.
141 142 * Note that many protocols, including http and zip, will already
142 143 * return false for is_file.
143 144 * A whitelist of protocols may be added if needed in future.
145 + * data: is intentionally allowed (see #4823); callers needing strict
146 + * on-disk-only semantics must validate $filename themselves.
144 147 */
145 148 public static function prohibitWrappers(string $filename): void
146 149 {
147 - $scheme = parse_url($filename, PHP_URL_SCHEME);
148 - // strlen check > 1 to avoid issues with Windows absolute paths (e.g. C:\...), Windows quirks :)
149 - // since no built-in or commonly registered PHP stream wrapper uses a single-character scheme, this should be ok, to my knowledge
150 - if (is_string($scheme) && strlen($scheme) > 1) {
150 + if (
151 + Preg::IsMatch('~^phar://~i', $filename)
152 + || (Preg::isMatch('/^([\w.\s\x00-\x1f]+):/', $filename) && !Preg::isMatch('/^([\w.]+):/', $filename))
153 + || Preg::isMatch('~^[\w.]+://.*phar:~is', $filename)
154 + ) {
151 155 throw new Exception(
152 - "Stream wrappers are not permitted as file paths: {$filename}"
156 + "Disallowed stream wrapper used for {$filename}"
153 157 );
154 158 }
155 159 }
156 160