CVE-2017-1000480

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
03/01/2018
Last modified:
04/02/2018

Description

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:* 3.0.0 (including) 3.1.32 (excluding)