Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-09-18T21:00:00
Updated: 2024-08-05T09:21:40.766Z
Reserved: 2018-07-11T00:00:00
Link: CVE-2018-13982
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-09-18T21:29:02.247
Modified: 2024-11-21T03:48:22.357
Link: CVE-2018-13982
Redhat
No data.