diff --git a/backup/util/xml/xml_writer.class.php b/backup/util/xml/xml_writer.class.php index 4673e4da3d4..e048fa431fb 100644 --- a/backup/util/xml/xml_writer.class.php +++ b/backup/util/xml/xml_writer.class.php @@ -262,7 +262,7 @@ class xml_writer { protected function xml_safe_utf8($content) { $content = preg_replace('/[\x-\x8\xb-\xc\xe-\x1f\x7f]/is', '', $content ?? ''); // clean CTRL chars. $content = preg_replace("/\r\n|\r/", "\n", $content); // Normalize line&return=>line - return $content; + return fix_utf8($content); } /** diff --git a/lib/moodlelib.php b/lib/moodlelib.php index 3fbe40341b4..6d344eb89b4 100644 --- a/lib/moodlelib.php +++ b/lib/moodlelib.php @@ -1318,8 +1318,9 @@ function fix_utf8($value) { // Shortcut. return $value; } - // No null bytes expected in our data, so let's remove it. - $value = str_replace("\0", '', $value); + + // Remove null bytes or invalid Unicode sequences from value. + $value = str_replace(["\0", "\xef\xbf\xbe", "\xef\xbf\xbf"], '', $value); // Note: this duplicates min_fix_utf8() intentionally. static $buggyiconv = null;