PHP Code Injection by malicious function name in smarty
Description
Published by the National Vulnerability Database
Feb 22, 2021
Reviewed
Feb 26, 2021
Published to the GitHub Advisory Database
Feb 26, 2021
Last updated
Feb 7, 2024
Template authors could inject php code by choosing a malicous {function} name. Sites that cannot fully trust template authors should update as soon as possible. Please upgrade to 3.1.39 or higher.
References