CVE-2018-13982

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
18/09/2018
Last modified:
02/11/2021

Description

Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:* 3.1.33 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*