Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-29gp-2c3m-3j6m

Опубликовано: 12 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Sandbox Escape by math function in smarty

Impact

Template authors could run arbitrary PHP code by crafting a malicious math string. If a math string is passed through as user provided data to the math function, external users could run arbitrary PHP code by crafting a malicious math string.

Patches

Please upgrade to 4.0.2 or 3.1.42 or higher.

References

See documentation on Math function.

For more information

If you have any questions or comments about this advisory please open an issue in the Smarty repo

Пакеты

Наименование

smarty/smarty

composer
Затронутые версииВерсия исправления

< 3.1.42

3.1.42

Наименование

smarty/smarty

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.2

4.0.2

EPSS

Процентиль: 70%
0.00643
Низкий

8.1 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 4 лет назад

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function, external users could run arbitrary PHP code by crafting a malicious math string. Users should upgrade to version 3.1.42 or 4.0.2 to receive a patch.

CVSS3: 8.1
nvd
около 4 лет назад

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function, external users could run arbitrary PHP code by crafting a malicious math string. Users should upgrade to version 3.1.42 or 4.0.2 to receive a patch.

CVSS3: 8.1
debian
около 4 лет назад

Smarty is a template engine for PHP, facilitating the separation of pr ...

CVSS3: 8.8
fstec
почти 5 лет назад

Уязвимость обработчика шаблонов для PHP Smarty, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный PHP-код

EPSS

Процентиль: 70%
0.00643
Низкий

8.1 High

CVSS3

Дефекты

CWE-74