fenom-template/fenom

fenom-template/fenom

Releases38
Frequency3 months 3 weeks
Last Release
Stars443
Template Engine for PHP.

CVE History

CVEPublishedCVSS v3CVSS v2
10 CRITICAL6.8 MEDIUM

In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.