Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-25047

Опубликовано: 15 сент. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 5.4

Описание

In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

esm-apps/bionic

released

3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1+esm1
esm-apps/focal

released

3.1.34+20190228.1.c9f0de05+selfpack1-1ubuntu0.1
esm-apps/jammy

released

3.1.39-2ubuntu1.22.04.2
esm-apps/noble

released

3.1.48-1ubuntu0.24.04.1
esm-apps/xenial

needs-triage

focal

released

3.1.34+20190228.1.c9f0de05+selfpack1-1ubuntu0.1
jammy

released

3.1.39-2ubuntu1.22.04.2
kinetic

ignored

end of life, was needs-triage

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

4.5.4-1
esm-apps/noble

not-affected

4.3.1-1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage
noble

not-affected

4.3.1-1

Показывать по

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.

CVSS3: 5.4
debian
больше 3 лет назад

In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.ma ...

CVSS3: 5.4
github
больше 3 лет назад

Smarty Cross-site Scripting vulnerability in pages that use smarty_function_mailto

5.4 Medium

CVSS3