smarty/smarty is vulnerable to arbitrary code injection. The vulnerability exists in smarty_function_math
function of function.math.php
because the math strings are not validated which allows an attacker to send and execute crafted malicious math strings.
github.com/smarty-php/smarty/commit/215d81a9fa3cd63d82fb3ab56ecaf97cf1e7db71
github.com/smarty-php/smarty/releases/tag/v3.1.42
github.com/smarty-php/smarty/releases/tag/v4.0.2
github.com/smarty-php/smarty/security/advisories/GHSA-29gp-2c3m-3j6m
lists.debian.org/debian-lts-announce/2022/05/msg00005.html
lists.fedoraproject.org/archives/list/[email protected]/message/BRAJVDRGCIY5UZ2PQHKDTT7RMKG6WJQQ/
lists.fedoraproject.org/archives/list/[email protected]/message/L777JIBIWJV34HS7LXPIDWASG7TT4LNI/
packagist.org/packages/smarty/smarty
security.gentoo.org/glsa/202209-09
www.debian.org/security/2022/dsa-5151
www.smarty.net/docs/en/language.function.math.tpl