PT-2021-23905 · Unknown · Matyhtf Framework

Published

2021-12-03

·

Updated

2021-12-06

·

CVE-2021-43676

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: matyhtf framework version 3.0.5
Description: The issue is a path manipulation vulnerability in the Smarty.class.php file. This vulnerability was fixed in version 3.0.6.
Recommendations: For matyhtf framework version 3.0.5, update to version 3.0.6 to resolve the issue. As a temporary workaround, consider restricting access to the Smarty.class.php file until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43676
GHSA-MH9J-V6MQ-PFCH

Affected Products

Matyhtf Framework