File tree Expand file tree Collapse file tree 1 file changed +2
-3
lines changed
lib/internal/Magento/Framework/Filter/Input Expand file tree Collapse file tree 1 file changed +2
-3
lines changed Original file line number Diff line number Diff line change 6
6
* See COPYING.txt for license details.
7
7
*/
8
8
9
- // @codingStandardsIgnoreFile
10
-
11
9
namespace Magento \Framework \Filter \Input ;
12
10
13
11
class MaliciousCode implements \Zend_Filter_Interface
@@ -29,7 +27,8 @@ class MaliciousCode implements \Zend_Filter_Interface
29
27
//js in the style attribute
30
28
'/style=[^<]*((expression\s*?\([^<]*?\))|(behavior\s*:))[^<]*(?=\/*\>)/Uis ' ,
31
29
//js attributes
32
- '/(ondblclick|onclick|onkeydown|onkeypress|onkeyup|onmousedown|onmousemove|onmouseout|onmouseover|onmouseup|onload|onunload|onerror)=[^<]*(?=\/*\>)/Uis ' ,
30
+ '/(ondblclick|onclick|onkeydown|onkeypress|onkeyup|onmousedown|onmousemove|onmouseout|onmouseover|onmouseup| ' .
31
+ 'onload|onunload|onerror)=[^<]*(?=\/*\>)/Uis ' ,
33
32
//tags
34
33
'/<\/?(script|meta|link|frame|iframe|object).*>/Uis ' ,
35
34
//base64 usage
You can’t perform that action at this time.
0 commit comments