CVE-2021-26120
22.02.2021, 02:15
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
Vendor | Product | Version |
---|---|---|
smarty | smarty | 𝑥 < 3.1.39 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
smarty3 |
|
References