CVE-2017-1000480Code Injection in Smarty

CWE-94Code Injection8 documents5 sources
Severity
9.8CRITICALNVD
EPSS
0.6%
top 29.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 3
Latest updateMay 14

Description

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDsmarty/smarty3.0.03.1.32
Packagistsmarty/smarty33.1.32
debiandebian/smarty3< smarty3 3.1.31+20161214.1.c7d42e4+selfpack1-3 (bookworm)

🔴Vulnerability Details

3
GHSA
Smarty PHP code injection2022-05-14
OSV
Smarty PHP code injection2022-05-14
OSV
CVE-2017-1000480: Smarty 3 before 32018-01-03

📋Vendor Advisories

1
Debian
CVE-2017-1000480: smarty3 - Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch(...2017

💬Community

3
Bugzilla
CVE-2017-1000480 php-Smarty: Code injection when calling fetch() or display() on unsanitized template names2018-01-09
Bugzilla
CVE-2017-1000480 php-Smarty: Code injection when calling fetch() or display() on unsanitized template names [epel-all]2018-01-09
Bugzilla
CVE-2017-1000480 php-Smarty: Code injection when calling fetch() or display() on unsanitized template names [fedora-all]2018-01-09