Skip to content

disable entity loader before parsing XML to avoid XXE injection #1427

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Jul 13, 2018

Conversation

troosan
Copy link
Contributor

@troosan troosan commented Jul 13, 2018

Description

XXE injection possible when parsing XML

Fixes #1421 by @Tom4t0

Checklist:

  • I have run composer run-script check --timeout=0 and no errors were reported
  • The new code is covered by unit tests (check build/coverage for coverage report)

@troosan troosan merged commit cdc1852 into PHPOffice:develop Jul 13, 2018
@troosan troosan deleted the libxml_disable_entity_loader branch July 13, 2018 23:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

1 participant