smarty Cross-site Scripting vulnerability in Javascript escaping
Package
Affected versions
>= 4.0.0, < 4.3.1
< 3.1.48
Patched versions
4.3.1
3.1.48
Description
Published by the National Vulnerability Database
Mar 28, 2023
Published to the GitHub Advisory Database
Mar 29, 2023
Reviewed
Mar 29, 2023
Last updated
Feb 1, 2024
Impact
An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user.
Patches
Please upgrade to the most recent version of Smarty v3 or v4.
For more information
If you have any questions or comments about this advisory please open an issue in the Smarty repo
References