Zen Cart Logo
Forums / Bug Reports / Uncaught TypeError: strip_tags(): Argument #1 ($string) must be of type string, array

Uncaught TypeError: strip_tags(): Argument #1 ($string) must be of type string, array

Views: 215

Results 1 to 4 of 4
1 Jul 2026, 5:34 PM
#1
jadebox avatar

jadebox

New Zenner

Join Date:
Jul 2009
Posts:
18
Plugin Contributions:
1

Uncaught TypeError: strip_tags(): Argument #1 ($string) must be of type string, array

Zen Cart 2.2.2

Parameters in the query string can be arrays, but the sanitation code in admin/includes/init_includes/init_general_funcs.php assumes that all the parameters are scalar and produces an error when an argument is an array.

if (isset($_GET) & sizeof($_GET) > 0 ) {
  foreach ($_GET as $key=>$value) {
     // Needs to check for an array .....
     $_GET[$key] = strip_tags($value);
  }
}
1 Jul 2026, 6:30 PM
#2
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,708
Plugin Contributions:
56

Re: Uncaught TypeError: strip_tags(): Argument #1 ($string) must be of type string, array

How do you reproduce this issue?

1 Jul 2026, 8:40 PM
#3
jadebox avatar

jadebox

New Zenner

Join Date:
Jul 2009
Posts:
18
Plugin Contributions:
1

Re: Uncaught TypeError: strip_tags(): Argument #1 ($string) must be of type string, array

swguy:

How do you reproduce this issue?

In my case, one of my plug-ins submits a form with radio buttons. You can simulate it by appending "&x[]=&x[]=" to a URL used when logged in as Admin. For example:

https://yoursite.com/shop/admin/index.php?cmd=category_product_listing&x[]=&x[]=

ETA: I just added "if (!is_array($value))" before the assignment, but a more robust fix would loop through the array.

But, since this is on the Admin side, I'm not sure that strip_tags really needs to be, or even should be, called on the arguments.

2 Jul 2026, 3:12 PM
#4
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Uncaught TypeError: strip_tags(): Argument #1 ($string) must be of type string, array

It's wiser to submit your forms via POST, instead of GET.

(We've intentionally excluded GET-array support, especially in the Admin, since sometime around the v1.5.0 era.)