Skip to content

PHP Code Injection by malicious function name

High
wisskid published GHSA-3rpf-5rqv-689q Feb 21, 2021

Package

composer smarty/smarty (Composer)

Affected versions

<3.1.39

Patched versions

3.1.39

Description

Impact

Template authors could inject php code by choosing a malicous {function} name. Sites that cannot fully trust template authors should update asap.

Patches

Please upgrade to 3.1.39 or higher.

References

See this article

For more information

If you have any questions or comments about this advisory please open an issue in the Smarty repo

Severity

High

CVE ID

CVE-2021-26120

Weaknesses

No CWEs

Credits