CVE-2021-29454

smarty/smarty
on packagist

Published

Severity

CVSS v3:
8.8 HIGH
CVSS v2:
6.5 MEDIUM

Description

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function, external users could run arbitrary PHP code by crafting a malicious math string. Users should upgrade to version 3.1.42 or 4.0.2 to receive a patch.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*n/a3.1.42*
cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*4.0.0 (including)4.0.2*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*n/an/a9.0
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*n/an/a10.0
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*n/an/a11.0
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*n/an/a36
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*n/an/a37

External Links