QID 997953
Date Published: 2024-04-08
QID 997953: PHP (Composer) Security Update for smarty/smarty (GHSA-6frx-2r5w-c524)
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6frx-2r5w-c524 for updates and patch information.
Vendor References
- GHSA-6frx-2r5w-c524 -
github.com/advisories/GHSA-6frx-2r5w-c524
CVEs related to QID 997953
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6frx-2r5w-c524 | smarty/smarty |
|