Lucene search

K
osvGoogleOSV:GHSA-65J5-VPM7-6XP4
HistoryMay 14, 2022 - 1:58 a.m.

Smarty Path Traversal Vulnerability

2022-05-1401:58:46
Google
osv.dev
11
smarty
path traversal
vulnerability
trusted_dir
include statement
software

EPSS

0.003

Percentile

71.5%

Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in an include statement.