CVE-2014-8350
smarty3 - security update
EPSS 0.47%
Description
Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.
How to fix CVE-2014-8350
To remediate CVE-2014-8350, upgrade the affected package to a fixed version below.
- Debian/smarty3—upgrade to 3.1.21-1 or later
- Debian/smarty3—upgrade to 3.1.10-2+deb7u1 or later
- Packagist/smarty/smarty—upgrade to 3.1.21 or later
Is CVE-2014-8350 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 3.1.21-1
- from 0, < 3.1.10-2+deb7u1
- from 0, < 3.1.21