Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4h9c-v5vg-5m6m

Опубликовано: 12 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Access to restricted PHP code by dynamic static class access in smarty

Impact

Template authors could run restricted static php methods.

Patches

Please upgrade to 3.1.40 or higher.

References

See the documentation on Smarty security features on the static_classes access filter.

For more information

If you have any questions or comments about this advisory please open an issue in the Smarty repo

Пакеты

Наименование

smarty/smarty

composer
Затронутые версииВерсия исправления

< 3.1.43

3.1.43

Наименование

smarty/smarty

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.3

4.0.3

EPSS

Процентиль: 64%
0.0047
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run restricted static php methods. Users should upgrade to version 3.1.43 or 4.0.3 to receive a patch.

CVSS3: 8.8
nvd
около 4 лет назад

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run restricted static php methods. Users should upgrade to version 3.1.43 or 4.0.3 to receive a patch.

CVSS3: 8.8
debian
около 4 лет назад

Smarty is a template engine for PHP, facilitating the separation of pr ...

EPSS

Процентиль: 64%
0.0047
Низкий

8.8 High

CVSS3

Дефекты

CWE-20