Description
Using unvalidated input as an include or require path may expose files or execute unintended PHP code. The files that can be included and the impact depend on file permissions, remote inclusion settings and other configuration.
Potential impact
Sensitive files may be exposed, authentication may be bypassed, or unintended PHP code may run.
Remediation
Fix includable files in a key-based allow-list. Do not use input directly as a path string.
Examples
Before
php
<?php
$file = $_GET['page'];
include($file);
After
php
<?php
$pages = [
'home' => __DIR__ . '/pages/home.php',
'help' => __DIR__ . '/pages/help.php',
];
$page = $_GET['page'] ?? 'home';
if (!isset($pages[$page])) {
http_response_code(404);
exit;
}
include $pages[$page];
Explanation:
- Before: User-controlled data reaches include or require, potentially exposing local files or executing unintended PHP code.
- After: Maps permitted keys to fixed files instead of using user input as a path.