NA

CVE-2018-25047

Published: 15/09/2022 Updated: 03/03/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

In Smarty prior to 3.1.47 and 4.x prior to 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

smarty smarty

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #1019896 smarty4: CVE-2018-25047: smarty_function_mailto - JavaScript injection in eval function Package: src:smarty4; Maintainer for src:smarty4 is Mike Gabriel <sunweaver@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 15 Sep 2022 19:51:01 UTC Severity: importa ...