MDL-45417 mod_imscp: Prevent entity injections from package content
This commit is contained in:
committed by
Dan Poltawski
parent
3b68d1b23a
commit
9b60a086cf
@@ -105,9 +105,11 @@ function imscp_parse_structure($imscp, $context) {
|
||||
*/
|
||||
function imscp_parse_manifestfile($manifestfilecontents) {
|
||||
$doc = new DOMDocument();
|
||||
$oldentities = libxml_disable_entity_loader(true);
|
||||
if (!$doc->loadXML($manifestfilecontents, LIBXML_NONET)) {
|
||||
return null;
|
||||
}
|
||||
libxml_disable_entity_loader($oldentities);
|
||||
|
||||
// we put this fake URL as base in order to detect path changes caused by xml:base attributes
|
||||
$doc->documentURI = 'http://grrr/';
|
||||
|
||||
Reference in New Issue
Block a user