High
CVSS 7.5
Overview
Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.
Smarty before 3.1.21 allows remote attackers to bypass the secure mode restricti...
Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.
This vulnerability is rated 🟠 HIGH.
Recommended actions: