From 4dc98b635d18527000e74a0eb4cd400db2bf5af3 Mon Sep 17 00:00:00 2001 From: Aidan Woods Date: Tue, 2 May 2017 19:48:08 +0100 Subject: [PATCH] whitelist changes: * add gif and jpg as allowed data images * ensure that user controlled content fall only in the "data section" of the data URI (and does not intersect content-type definition in any way (best to be safe than sorry ;-))) "data section" as defined in: https://tools.ietf.org/html/rfc2397#section-3 --- Parsedown.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/Parsedown.php b/Parsedown.php index d42e4f5..7e72d69 100644 --- a/Parsedown.php +++ b/Parsedown.php @@ -91,7 +91,9 @@ class Parsedown 'ftp://', 'ftps://', 'mailto:', - 'data:image/png;', + 'data:image/png;base64,', + 'data:image/gif;base64,', + 'data:image/jpg;base64,', ); #