Just noticed a stupid oversight: if you set no tag boosts in the HTML filter, it just does a strip_tags() on the value – and no html_entity_decode() to also get rid of HTML entities in the value (which otherwise does happen correctly).

Comments

drunken monkey’s picture

Status: Active » Needs review
StatusFileSize
new580 bytes

Trivial patch attached, also seems to work fine.

joelpittet’s picture

+++ b/includes/processor_html_filter.inc
@@ -101,7 +101,7 @@ class SearchApiHtmlFilter extends SearchApiAbstractProcessor {
-      $value = strip_tags($text);
+      $value = html_entity_decode(strip_tags($text));

Any chance this could lead to XSS issue?

php -r 'var_dump(html_entity_decode(strip_tags("<script>alert(\"XSS\")")));'

Otherwise this is good.

  • drunken monkey committed 0580e94 on 7.x-1.x
    Issue #2419853 by drunken monkey: Fixed HTML filter leaves escaped...
drunken monkey’s picture

Status: Needs review » Fixed

Any chance this could lead to XSS issue?

Yes, it can, thanks a lot for spotting this! See the security announcement.

But with that out of the way, I think we can finally commit this.
Thanks again for the review!

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.