Lucene search

K
osvGoogleOSV:GHSA-9M49-VHWV-422G
HistoryMay 14, 2022 - 3:46 a.m.

Smarty PHP code injection

2022-05-1403:46:35
Google
osv.dev
9
smarty
php
code injection
vulnerability
fetch
display
custom resources
template name
un-sanitized

AI Score

7.1

Confidence

Low

EPSS

0.004

Percentile

73.9%

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

AI Score

7.1

Confidence

Low

EPSS

0.004

Percentile

73.9%