Files
Wallos/includes/ical_helper.php
Miguel Ribeiro 11eaf402e8 feat!: complete ui overhaul (#1108)
feat: option for the week to start on sunday
feat: redesign login / registration pages
feat: more statistics
feat: declarative oidc settings
feat: grid view for subscriptions
feat: subscription details popup
feat: translate categories with ai
feat: google image search with serpapi
feat: selfh.st image search
feat: dashboard icons image search
fix: improve background removal feature for logos
feat: v2.0 api - write endpoints
fix: include todays subscriptions on amount due this month
fix: calendar occurrences to respect subscription start date
fix: honor configured outbound proxy for logo search without reopening httpoxy SSRF bypass
fix: remove hardcode string from the admin page
fix: ssrf via http proxy env var in payments logo search
fix: require cron auth guard on storetotalyearlycost.php
fix: validate per-user smtp host against ssrf
fix: escape iCal property values to prevent crlf injection
2026-07-11 23:54:52 +02:00

24 lines
829 B
PHP

<?php
/**
* Escapes a value for safe embedding in an iCalendar (RFC 5545) property value.
*
* Backslash must be escaped first, before the other substitutions introduce
* new backslashes. Raw CRLF/LF are converted to a literal two-character
* "\n" escape sequence — never leave a real newline in the output, since
* iCalendar treats CRLF as a property delimiter: an unescaped newline lets
* user-supplied text (e.g. a subscription name or notes) terminate the
* current property and inject arbitrary calendar content (CWE-93).
*/
function icalEscape($value)
{
$value = (string) $value;
$value = str_replace('\\', '\\\\', $value);
$value = str_replace(["\r\n", "\r", "\n"], '\\n', $value);
$value = str_replace(',', '\\,', $value);
$value = str_replace(';', '\\;', $value);
return $value;
}
?>