CVE-2018-13982
EUVD-2022-299518.09.2018, 21:29
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| smarty | smarty | 𝑥 < 3.1.33 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases