← All changes
|
libraries/vendor/PhpSpreadsheet/Reader/Security/XmlScanner.php
+5
-0
3.3.3
→
3.4
View file →
| @@ -124,8 +124,13 @@ | ||
| 124 | 124 | if ($foundUtf7) { |
| 125 | 125 | throw new Reader\Exception('UTF-7 encoding not permitted'); |
| 126 | 126 | } |
| 127 | 127 | if (substr($xml, 0, Reader\Csv::UTF8_BOM_LEN) === Reader\Csv::UTF8_BOM) { |
| 128 | + if (preg_match(self::ENCODING_PATTERN, $xml, $matches) === 1) { | |
| 129 | + if (strtolower($matches[2]) !== 'utf-8') { | |
| 130 | + throw new Reader\Exception("BOM says UTF-8 but encoding says {$matches[2]}"); | |
| 131 | + } | |
| 132 | + } | |
| 128 | 133 | $xml = (string) substr($xml, Reader\Csv::UTF8_BOM_LEN); |
| 129 | 134 | } |
| 130 | 135 | |
| 131 | 136 | return $xml; |