PT-2018-5245 · Smarty · Smarty

Published

2018-01-03

·

Updated

2022-05-14

·

CVE-2017-1000480

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Smarty 3 versions prior to 3.1.32
Description The issue arises from a PHP code injection vulnerability when calling fetch() or display() functions on custom resources that do not sanitize the template name.
Recommendations For versions prior to 3.1.32, update to version 3.1.32 or later to resolve the issue.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000480
DLA-1249-1
DSA-4094-1
DSA-4094-2
GHSA-9M49-VHWV-422G
MGASA-2018-0118

Affected Products

Smarty