['Hello, I am safely viewing your site', 'Hello, I am safely viewing your site'], 'link eliminated' => ["Google is here", "<a href='Visit Google'>Google is here</a>"], 'script tag' => ["Hello, I am trying to your site", "Hello, I am trying to <script>alert('Hack');</script> your site"], 'script tag with quotes' => ['Hello, I am trying to your site', 'Hello, I am trying to <script>alert("Hack");</script> your site'], 'javascript tag no hex' => ["CLICK", "<a href='javascript:alert(1)'>CLICK</a>"], 'javascript tag' => ["CLICK", "<a href='&#x2000;javascript:alert(1)'>CLICK</a>"], 'with unicode' => ['CLICK', '<a href="\u0001java\u0003script:alert(1)">CLICK</a>'], 'inline css' => ['
  • ', '<li style="list-style-image: url(javascript:alert(0))">'], 'char value chevron' => ["\x3cscript src=http://www.example.com/malicious-code.js\x3e\x3c/script\x3e", '<script src=http://www.example.com/malicious-code.js></script>'], 'hexadecimal html' => ['', '<IMG SRC=&#106&#x61&#x76&#x61&#x73&#109&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29>'], 'iframe' => ['', '<iframe width="560" onclick="alert(\'xss\')" height="315" src="https://www.youtube.com/embed/whatever?rel=0&controls=0&showinfo=0" frameborder="0" allowfullscreen></iframe>'], ]; } #[\PHPUnit\Framework\Attributes\DataProvider('providerXssRichText')] public function testXssInComment(string $xssTextString, ?string $expected = null): void { $spreadsheet = new Spreadsheet(); $startCell = ''; $cellText = 'XSS Test'; $endCell = $cellText . ''; $richText = new RichText(); $richText->createText($xssTextString); $spreadsheet->getActiveSheet()->getCell('A1') ->setValue($cellText); $spreadsheet->getActiveSheet() ->getComment('A1') ->setText($richText); $writer = new Html($spreadsheet); $eol = $writer->getLineEnding(); if ($expected === null) { // whole comment stripped away $expected = $startCell . $endCell; } else { $expected = $startCell . '
    ' . $expected . '
    ' . $eol . $endCell; } $verify = $writer->generateHtmlAll(); // Ensure that executable js has been stripped from the comments self::assertStringContainsString($expected, $verify); $spreadsheet->disconnectWorksheets(); } public function testXssInFontName(): void { $spreadsheet = new Spreadsheet(); $sheet = $spreadsheet->getActiveSheet(); $sheet->getCell('A1')->setValue('here'); $used = 'Calibri