Lucene search

K
osvGoogleOSV:GHSA-7GFX-WXFH-7RVM
HistoryMay 13, 2022 - 1:05 a.m.

Smarty Path Traversal Vulnerability

2022-05-1301:05:24
Google
osv.dev
24
smarty
path traversal
vulnerability
template code
sanitization
security restriction
arbitrary files

EPSS

0.003

Percentile

69.8%

Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.

References