Skip to content

Cross site scripting vulnerability in Javascript escaping

Moderate
wisskid published GHSA-7j98-h7fp-4vwj Mar 28, 2023

Package

composer smarty/smarty (Composer)

Affected versions

<4.3.1
<3.1.48

Patched versions

4.3.1
3.1.48

Description

Impact

An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user.

Patches

Please upgrade to the most recent version of Smarty v3 or v4.

For more information

If you have any questions or comments about this advisory please open an issue in the Smarty repo

Severity

Moderate

CVE ID

CVE-2023-28447

Weaknesses

No CWEs

Credits