Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33596
HistoryJan 11, 2022 - 3:52 p.m.

Improper Input Validation

2022-01-1115:52:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
improper input validation
smarty
vulnerability
security settings
dynamic static class
restricted code

EPSS

0.002

Percentile

58.5%

smarty/smarty is vulnerable to improper input validation. The vulnerability exists in smarty_internal_templateparser.php because the security settings are not properly defined which allows an attacker to the restricted code through dynamic static class.