['Hello, I am safely viewing your site', 'Hello, I am safely viewing your site'], 'link no problem' => ["Google is here", "Google is here"], 'script tag' => ["Hello, I am trying to your site", 'Hello, I am trying to your site'], 'javascript tag no hex' => ["CLICK", "CLICK"], 'javascript tag' => ["CLICK", "CLICK"], 'with unicode' => ['CLICK', 'CLICK'], 'inline css' => ['
  • ', '
  • '], 'char value chevron' => ["\x3cscript src=http://www.example.com/malicious-code.js\x3e\x3c/script\x3e"], 'hexadecimal html' => ['', ''], 'iframe' => ['', '<iframe width="560" height="315" src="https://www.youtube.com/embed/whatever?rel=0&controls=0&showinfo=0" frameborder="0" allowfullscreen></iframe>'], ]; } /** * @dataProvider providerXssRichText */ public function testXssInComment(string $xssTextString, ?string $expected = null): void { $spreadsheet = new Spreadsheet(); $startCell = ''; $cellText = 'XSS Test'; $endCell = $cellText . ''; if ($expected === null) { // whole comment stripped away $expected = $startCell . $endCell; } else { $expected = $startCell . '
    ' . $expected . '
    ' . PHP_EOL . $endCell; } $richText = new RichText(); $richText->createText($xssTextString); $spreadsheet->getActiveSheet()->getCell('A1')->setValue($cellText); $spreadsheet->getActiveSheet() ->getComment('A1') ->setText($richText); $writer = new Html($spreadsheet); $verify = $writer->generateHtmlAll(); // Ensure that executable js has been stripped from the comments self::assertStringContainsString($expected, $verify); $spreadsheet->disconnectWorksheets(); } }