Количество 3
Количество 3
CVE-2026-62992
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating that a requested path lies within a configured secure directory. An attacker able to place or reference a symlink within a directory Smarty treats as trusted (e.g., a template or config directory) could use it to point outside the intended secure directory, bypassing the containment check and reading arbitrary files accessible to the PHP process. This issue is fixed in versions 5.8.2 and 4.5.7.
CVE-2026-62992
Smarty is a template engine for PHP, facilitating the separation of pr ...
GHSA-f6wf-28g6-769x
Smarty: Symlink path traversal out of trusted directories
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-62992 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating that a requested path lies within a configured secure directory. An attacker able to place or reference a symlink within a directory Smarty treats as trusted (e.g., a template or config directory) could use it to point outside the intended secure directory, bypassing the containment check and reading arbitrary files accessible to the PHP process. This issue is fixed in versions 5.8.2 and 4.5.7. | 0% Низкий | 4 дня назад | ||
CVE-2026-62992 Smarty is a template engine for PHP, facilitating the separation of pr ... | 0% Низкий | 4 дня назад | ||
GHSA-f6wf-28g6-769x Smarty: Symlink path traversal out of trusted directories | 0% Низкий | 4 дня назад |
Уязвимостей на страницу