Lucene search

K
osvGoogleOSV:GHSA-4H9C-V5VG-5M6M
HistoryJan 12, 2022 - 10:43 p.m.

Access to restricted PHP code by dynamic static class access in smarty

2022-01-1222:43:42
Google
osv.dev
16
php code
dynamic static class
smarty
security
upgrade
documentation
static classes access filter
advisory
issue
software

EPSS

0.002

Percentile

58.5%

Impact

Template authors could run restricted static php methods.

Patches

Please upgrade to 3.1.40 or higher.

References

See the documentation on Smarty security features on the static_classes access filter.

For more information

If you have any questions or comments about this advisory please open an issue in the Smarty repo