Skip to content

Access to restricted PHP code by dynamic static class access

High
wisskid published GHSA-4h9c-v5vg-5m6m Jan 10, 2022

Package

composer smarty/smarty (Composer)

Affected versions

< 3.1.43
< 4.0.3

Patched versions

3.1.43
4.0.3

Description

Impact

Template authors could run restricted static php methods.

Patches

Please upgrade to 3.1.40 or higher.

References

See the documentation on Smarty security features on the static_classes access filter.

For more information

If you have any questions or comments about this advisory please open an issue in the Smarty repo

Severity

High

CVE ID

CVE-2021-21408

Weaknesses

No CWEs