TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2021-29454

HIGH
8.1

Beschreibung

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function, external users could run arbitrary PHP code by crafting a malicious math string. Users should upgrade to version 3.1.42 or 4.0.2 to receive a patch.

CVE Details

CVSS v3.1 Bewertung8.1
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht1/10/2022
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

debian:debian_linuxfedoraproject:fedorasmarty:smarty

Schwachen (CWE)

CWE-74CWE-74

Referenzen

https://packagist.org/packages/smarty/smarty(security-advisories@github.com)
https://security.gentoo.org/glsa/202209-09(security-advisories@github.com)
https://www.debian.org/security/2022/dsa-5151(security-advisories@github.com)
https://github.com/smarty-php/smarty/releases/tag/v3.1.42(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/smarty-php/smarty/releases/tag/v4.0.2(af854a3a-2127-422b-91ae-364da2661108)
https://packagist.org/packages/smarty/smarty(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/202209-09(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2022/dsa-5151(af854a3a-2127-422b-91ae-364da2661108)
https://www.smarty.net/docs/en/language.function.math.tpl(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.