Debian Smarty4 vulnerabilities
2 known vulnerabilities affecting debian/smarty4.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-28447HIGHCVSS 7.1fixed in smarty3 3.1.47-2+deb12u1 (bookworm)2023
CVE-2023-28447 [HIGH] CVE-2023-28447: smarty3 - Smarty is a template engine for PHP. In affected versions smarty did not properl...
Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions p
debian
CVE-2018-25047MEDIUMCVSS 5.4fixed in smarty3 3.1.47-1 (bookworm)2018
CVE-2018-25047 [MEDIUM] CVE-2018-25047: smarty3 - In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php a...
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
Scope: local
bookworm: resolved (fixed in 3.1.47-1)
bullseye: resolved (fixed in 3.1.39-2+deb11u2)
forky: reso
debian