Lucene search

K
osvGoogleOSV:GHSA-3RPF-5RQV-689Q
HistoryFeb 26, 2021 - 7:53 p.m.

PHP Code Injection by malicious function name in smarty

2021-02-2619:53:24
Google
osv.dev
21
php code injection
smarty template
malicious function
software update

EPSS

0.011

Percentile

84.8%

Template authors could inject php code by choosing a malicous {function} name. Sites that cannot fully trust template authors should update as soon as possible. Please upgrade to 3.1.39 or higher.