Logo
vulnerabilityCVE-2023-28447
Name
CVE-2023-28447
Source
NVD ( link)Debian ( link)
Description
Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
smarty
Patched

Vulnerability Ratings#


7.1
CVSSv31
6.1
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
5.8.0
Not Affected
yocto
scarthgap
4.4.1
Not Affected

Resolved with patches#


smarty (yocto:kirkstone)

#
Title
Author
Resolve
1
Implement fix and tests
Simon Wisselink <s.wisselink@iwink.nl>
CVE-2023-28447