Skip to content

PHP Code Injection by malicious attribute in extends-tag

High
wisskid published GHSA-4rmg-292m-wg3w May 28, 2024

Package

composer smarty/smarty (Composer)

Affected versions

3.*.*
<4.5.3
<5.2.0

Patched versions

4.5.3
5.2.0

Description

Impact

Template authors could inject php code by choosing a malicous file name for an extends-tag. Users that cannot fully trust template authors should update asap.

Patches

Please upgrade to the most recent version of Smarty v4 or v5. There is no patch for v3.

Severity

High

CVE ID

CVE-2024-35226

Weaknesses

No CWEs

Credits