Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-18T21:00:00

Updated: 2024-08-05T09:21:40.766Z

Reserved: 2018-07-11T00:00:00

Link: CVE-2018-13982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-09-18T21:29:02.247

Modified: 2021-11-02T14:01:02.210

Link: CVE-2018-13982

cve-icon Redhat

No data.