CVE-2024-35226

HIGH7.3EPSS 0.28%

Smarty vulnerable to PHP Code Injection by malicious attribute in extends-tag

Published: 5/29/2024Modified: 11/4/2025
Also known as:GHSA-4rmg-292m-wg3w

Description

### Impact Template authors could inject php code by choosing a malicous file name for an extends-tag. Users that cannot fully trust template authors should update asap. ### Patches Please upgrade to the most recent version of Smarty v4 or v5. There is no patch for v3.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.3CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

References (6)