Security update for the bkvsoft.webp module.
This update includes fixes aimed at enhancing the security of the administrative interface, AJAX handlers, and bulk image conversion operations.
Key changes:
1. Strengthened protection of the module's AJAX endpoint.
- Mandatory administrator permission checks have been added for administrative AJAX methods.
- Bitrix sessid verification has been added to protect against CSRF.
- Only the webp image processing scenario remains public.
- The sessid is now passed in all AJAX requests within the administrative interface JavaScript.
2. Closed the CSRF vector during module settings saving.
- Server-side check_bitrix_sessid() verification has been added to the parameter saving handler.
- This check is performed before any module settings are modified.
3. Strengthened handling of user-defined regular expressions.
- Validation of user-defined PCRE patterns has been added.
- A pattern length limit has been introduced.
- Control characters and potentially dangerous ReDoS constructs are now filtered.
- Regular expression compilation is now verified before use.
- Fixed handling of callback results when no capture group is present.
4. Fixed potential stored XSS vectors in the administrative interface.
- The image_search_page_custom_regexp value is now escaped when output to a textarea via htmlspecialcharsbx().
- The site_exeptions_page value is now escaped when output to a textarea via htmlspecialcharsbx().
- Additional dynamic values output in the HTML context of the administrative page are now escaped.
5. Strengthened module settings handling.
- Safe deserialization with allowed_classes => false has been added for serialized options.
- Normalization of site_exeptions_page values has been added before saving.
- Normalization of image_search_page_custom_regexp values has been added before saving.
- Fixed comparison of the current site_exeptions_page value when saving settings.
6. Strengthened SQL query when updating b_file records.
- The file name is escaped via $DB->ForSql().
- Numeric values FILE_ID and FILE_SIZE are cast to int.
- Unsafe substitution of string values into the SQL query has been eliminated.
7. Strengthened generation of administrative PHP files for the module.
- Added an allowlist of permitted files for the administrative interface.
- Automatic generation of PHP stubs for arbitrary files from the admin/ directory has been eliminated.
- Added a check for the file name and .php extension.
8. Additional hardening of administrative code performed.
- Strengthened the check of the user object before calling IsAdmin().
- Fixed an HTML error in the title attribute of the .htaccess check button.
- Reduced risks of incorrect processing of corrupted or empty service options.
The update is recommended for all module users.