Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7466
HistorySep 12, 2018 - 5:02 a.m.

Directory Traversal

2018-09-1205:02:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

EPSS

0.003

Percentile

71.6%

smarty/smarty is vulnerable to directory traversal attacks. The vulnerability exists due to the lack of sanitization of file path that allows the external files to be references through trusted_dir, causing a directory traversal attack. This issue is also referenced in CVE-2018-13982.