From 17b8efa585fb5836a803a91d52c0f8af267eeadf Mon Sep 17 00:00:00 2001 From: Frederic Massart Date: Wed, 4 Mar 2015 16:00:32 +0100 Subject: [PATCH] MDL-49179 weblib: Secure the direct usage of $_SERVER['HTTP_REFERER'] --- auth/ldap/auth.php | 3 ++- course/togglecompletion.php | 5 +++-- login/index.php | 4 +++- mod/choice/view.php | 2 +- mod/forum/lib.php | 8 ++------ mod/forum/post.php | 5 ++--- mod/survey/save.php | 2 +- mod/wiki/filesedit.php | 5 +++-- user/view.php | 10 ++++++---- 9 files changed, 23 insertions(+), 21 deletions(-) diff --git a/auth/ldap/auth.php b/auth/ldap/auth.php index 4c5f736a563..b2ff306e38d 100644 --- a/auth/ldap/auth.php +++ b/auth/ldap/auth.php @@ -1653,7 +1653,8 @@ class auth_plugin_ldap extends auth_plugin_base { $_SERVER['HTTP_REFERER'] != $CFG->wwwroot && $_SERVER['HTTP_REFERER'] != $CFG->wwwroot.'/' && $_SERVER['HTTP_REFERER'] != $CFG->httpswwwroot.'/login/' && - $_SERVER['HTTP_REFERER'] != $CFG->httpswwwroot.'/login/index.php') + $_SERVER['HTTP_REFERER'] != $CFG->httpswwwroot.'/login/index.php' && + clean_param($_SERVER['HTTP_REFERER'], PARAM_LOCALURL) != '') ? $_SERVER['HTTP_REFERER'] : NULL; } diff --git a/course/togglecompletion.php b/course/togglecompletion.php index 234b8c89e09..075134fe8d8 100644 --- a/course/togglecompletion.php +++ b/course/togglecompletion.php @@ -78,8 +78,9 @@ if ($courseid) { } // Return to previous page - if (!empty($_SERVER['HTTP_REFERER'])) { - redirect($_SERVER['HTTP_REFERER']); + $referer = clean_param($_SERVER['HTTP_REFERER'], PARAM_LOCALURL); + if (!empty($referer)) { + redirect($referer); } else { redirect('view.php?id='.$course->id); } diff --git a/login/index.php b/login/index.php index 587eb0efec4..179651b6422 100644 --- a/login/index.php +++ b/login/index.php @@ -257,7 +257,9 @@ if (empty($SESSION->wantsurl)) { $_SERVER["HTTP_REFERER"] != $CFG->wwwroot.'/' && $_SERVER["HTTP_REFERER"] != $CFG->httpswwwroot.'/login/' && strpos($_SERVER["HTTP_REFERER"], $CFG->httpswwwroot.'/login/?') !== 0 && - strpos($_SERVER["HTTP_REFERER"], $CFG->httpswwwroot.'/login/index.php') !== 0) // There might be some extra params such as ?lang=. + strpos($_SERVER["HTTP_REFERER"], $CFG->httpswwwroot.'/login/index.php') !== 0 && + clean_param($_SERVER['HTTP_REFERER'], PARAM_LOCALURL) != '') + // There might be some extra params such as ?lang=. ? $_SERVER["HTTP_REFERER"] : NULL; } diff --git a/mod/choice/view.php b/mod/choice/view.php index c9900e5037a..a43b72bd43a 100644 --- a/mod/choice/view.php +++ b/mod/choice/view.php @@ -170,7 +170,7 @@ if (!$choiceformshown) { } else if (!is_enrolled($context)) { // Only people enrolled can make a choice $SESSION->wantsurl = qualified_me(); - $SESSION->enrolcancel = (!empty($_SERVER['HTTP_REFERER'])) ? $_SERVER['HTTP_REFERER'] : ''; + $SESSION->enrolcancel = clean_param($_SERVER['HTTP_REFERER'], PARAM_LOCALURL); $coursecontext = context_course::instance($course->id); $courseshortname = format_string($course->shortname, true, array('context' => $coursecontext)); diff --git a/mod/forum/lib.php b/mod/forum/lib.php index 0dc2627e5d7..ecf31c6a97a 100644 --- a/mod/forum/lib.php +++ b/mod/forum/lib.php @@ -3930,14 +3930,10 @@ function forum_set_return() { global $CFG, $SESSION; if (! isset($SESSION->fromdiscussion)) { - if (!empty($_SERVER['HTTP_REFERER'])) { - $referer = $_SERVER['HTTP_REFERER']; - } else { - $referer = ""; - } + $referer = clean_param($_SERVER['HTTP_REFERER'], PARAM_LOCALURL); // If the referer is NOT a login screen then save it. if (! strncasecmp("$CFG->wwwroot/login", $referer, 300)) { - $SESSION->fromdiscussion = $_SERVER["HTTP_REFERER"]; + $SESSION->fromdiscussion = $referer; } } } diff --git a/mod/forum/post.php b/mod/forum/post.php index b471a5e9b14..e790fd46d73 100644 --- a/mod/forum/post.php +++ b/mod/forum/post.php @@ -117,7 +117,7 @@ if (!empty($forum)) { // User is starting a new discussion in a forum if (!is_enrolled($coursecontext)) { if (enrol_selfenrol_available($course->id)) { $SESSION->wantsurl = qualified_me(); - $SESSION->enrolcancel = $_SERVER['HTTP_REFERER']; + $SESSION->enrolcancel = clean_param($_SERVER['HTTP_REFERER'], PARAM_LOCALURL); redirect($CFG->wwwroot.'/enrol/index.php?id='.$course->id, get_string('youneedtoenrol')); } } @@ -135,7 +135,6 @@ if (!empty($forum)) { // User is starting a new discussion in a forum $SESSION->fromurl = ''; } - // Load up the $post variable. $post = new stdClass(); @@ -187,7 +186,7 @@ if (!empty($forum)) { // User is starting a new discussion in a forum if (!isguestuser()) { if (!is_enrolled($coursecontext)) { // User is a guest here! $SESSION->wantsurl = qualified_me(); - $SESSION->enrolcancel = $_SERVER['HTTP_REFERER']; + $SESSION->enrolcancel = clean_param($_SERVER['HTTP_REFERER'], PARAM_LOCALURL); redirect($CFG->wwwroot.'/enrol/index.php?id='.$course->id, get_string('youneedtoenrol')); } } diff --git a/mod/survey/save.php b/mod/survey/save.php index 139ceb90e70..0cf2613d746 100644 --- a/mod/survey/save.php +++ b/mod/survey/save.php @@ -70,7 +70,7 @@ echo $OUTPUT->heading($survey->name); if (survey_already_done($survey->id, $USER->id)) { - notice(get_string("alreadysubmitted", "survey"), $_SERVER["HTTP_REFERER"]); + notice(get_string("alreadysubmitted", "survey"), clean_param($_SERVER["HTTP_REFERER"], PARAM_LOCALURL)); exit; } diff --git a/mod/wiki/filesedit.php b/mod/wiki/filesedit.php index fe5a159523d..6d391614e39 100644 --- a/mod/wiki/filesedit.php +++ b/mod/wiki/filesedit.php @@ -60,8 +60,9 @@ if (!wiki_user_can_view($subwiki, $wiki)) { require_capability('mod/wiki:managefiles', $context); if (empty($returnurl)) { - if (!empty($_SERVER["HTTP_REFERER"])) { - $returnurl = $_SERVER["HTTP_REFERER"]; + $refere = clean_param($_SERVER["HTTP_REFERER"], PARAM_LOCALURL); + if (!empty($referer)) { + $returnurl = $referer; } else { $returnurl = new moodle_url('/mod/wiki/files.php', array('subwiki'=>$subwiki->id)); } diff --git a/user/view.php b/user/view.php index 1805328ee0d..fb215714cc5 100644 --- a/user/view.php +++ b/user/view.php @@ -112,8 +112,9 @@ if ($currentuser) { // Need to have full access to a course to see the rest of own info. echo $OUTPUT->header(); echo $OUTPUT->heading(get_string('notenrolled', '', $fullname)); - if (!empty($_SERVER['HTTP_REFERER'])) { - echo $OUTPUT->continue_button($_SERVER['HTTP_REFERER']); + $referer = clean_param($_SERVER['HTTP_REFERER'], PARAM_LOCALURL); + if (!empty($referer)) { + echo $OUTPUT->continue_button($referer); } echo $OUTPUT->footer(); die; @@ -143,8 +144,9 @@ if ($currentuser) { $PAGE->navbar->add($struser); echo $OUTPUT->heading(get_string('notenrolledprofile')); } - if (!empty($_SERVER['HTTP_REFERER'])) { - echo $OUTPUT->continue_button($_SERVER['HTTP_REFERER']); + $referer = clean_param($_SERVER['HTTP_REFERER'], PARAM_LOCALURL); + if (!empty($referer)) { + echo $OUTPUT->continue_button($referer); } echo $OUTPUT->footer(); exit;