Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Takaram

#38997of 53,632
7.1Total CVSS
Vulnerabilities · 1
PT-2023-21728
7.1
2023-03-28
Smarty · Smarty · CVE-2023-28447
**Name of the Vulnerable Software and Affected Versions** Smarty versions prior to 3.1.48 Smarty versions prior to 4.3.1 **Description** The issue is related to improper escaping of JavaScript code in the Smarty template engine for PHP. An attacker could exploit this to execute arbitrary JavaScript code in the context of the user's browser session, potentially leading to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user. **Recommendations** To resolve this issue, users are advised to upgrade to either version 3.1.48 or version 4.3.1. For versions prior to 3.1.48, upgrade to version 3.1.48. For versions prior to 4.3.1, upgrade to version 4.3.1.