PT-2023-21728 · Smarty+2 · Smarty+2

Takaram

·

Published

2023-03-28

·

Updated

2026-05-19

·

CVE-2023-28447

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Smarty versions prior to 3.1.48 Smarty versions prior to 4.3.1
Description The issue is related to improper escaping of JavaScript code in the Smarty template engine for PHP. An attacker could exploit this to execute arbitrary JavaScript code in the context of the user's browser session, potentially leading to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user.
Recommendations To resolve this issue, users are advised to upgrade to either version 3.1.48 or version 4.3.1. For versions prior to 3.1.48, upgrade to version 3.1.48. For versions prior to 4.3.1, upgrade to version 4.3.1.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-28447
DLA-3956-1
DSA-5826-1
GHSA-7J98-H7FP-4VWJ
MGASA-2023-0155
USN-6550-1
USN-7158-1
USN-8242-1
USN-8242-2
USN-8272-1

Affected Products

Linuxmint
Smarty
Ubuntu