Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35688
HistoryMay 25, 2022 - 5:09 a.m.

Arbitrary Code Injection

2022-05-2505:09:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
arbitrary code injection
smarty
vulnerability
incorrect logic
template function
malicious code

EPSS

0.003

Percentile

69.6%

smarty/smarty is vulnerable to arbitrary code injection. The vulnerability exists due to incorrect logic in block name and include file name assignments in setting buffer for template function which allows an attacker to inject and execute malicious code.