Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13372
HistoryFeb 25, 2019 - 8:11 a.m.

PHP Code Injection

2019-02-2508:11:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

EPSS

0.004

Percentile

73.9%

smarty-php/smarty is vulnerable to PHP code injection attacks. The vulnerability exists as the template names are unsanitized when called from fetch() or display(), allowing PHP code injection attacks.