Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33595
HistoryJan 11, 2022 - 3:31 p.m.

Arbitrary Code Injection

2022-01-1115:31:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
arbitrary code injection
smarty
function.math.php
software vulnerability

EPSS

0.003

Percentile

69.7%

smarty/smarty is vulnerable to arbitrary code injection. The vulnerability exists in smarty_function_math function of function.math.php because the math strings are not validated which allows an attacker to send and execute crafted malicious math strings.