Better fix for XSS in style tags (fa2824fdc)

pull/5754/head 1.2.4
Thomas Bruederli 7 years ago
parent fa2824fdcd
commit cbd35626f7

@ -499,10 +499,10 @@ class rcube_utils
public static function xss_entity_decode($content)
{
$out = html_entity_decode(html_entity_decode($content));
$out = strip_tags($out);
$out = preg_replace_callback('/\\\([0-9a-f]{4})/i',
array(self, 'xss_entity_decode_callback'), $out);
$out = preg_replace('#/\*.*\*/#Ums', '', $out);
$out = strip_tags($out);
return $out;
}

Loading…
Cancel
Save