CVE-2012-4437 — Cross-site Scripting in Smarty
Severity
4.3MEDIUMNVD
EPSS
0.6%
top 31.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Latest updateMay 17
Description
Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages3 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2012-4437: smarty3 - Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty ...↗2012
💬Community
3Bugzilla▶
CVE-2012-4437 php-Smarty: XSS due improper sanitization of messages within SmartyException [epel-5]↗2013-03-11
Bugzilla▶
CVE-2012-4437 php-Smarty: XSS due improper sanitization of messages within SmartyException [fedora-rawhide]↗2012-09-20
Bugzilla▶
CVE-2012-4437 php-Smarty: XSS due improper sanitization of messages within SmartyException↗2012-09-20