CVE-2018-25047
15.09.2022, 00:15
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
Vendor | Product | Version |
---|---|---|
smarty | smarty | 𝑥 < 3.1.47 |
smarty | smarty | 4.0.0 ≤ 𝑥 < 4.2.1 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References