VDB

CVE-2022-29221

CVE-2022-29221 PUBLISHED CVSS 8.800000190734863 HIGH

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully trust template authors should upgrade to versions 3.1.45 or 4.1.1 to receive a patch for this issue. There are currently no known workarounds.

EPSS 25.50% · 96.3th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
25.50%
96.3th percentile

Affected Products

VendorProductVersions
smartysmarty0, 4.0.0
fedoraprojectfedora36, 37
smarty-phpsmarty< 3.1.45, >= 4.0.0, < 4.1.1
smartysmarty0, 4.0.0
debiandebian_linux10.0, 9.0, 11.0

Timeline

  • May 24, 2022 CVE Published
  • May 25, 2022 EPSS Score
  • Jun 7, 2022 EPSS Score
  • Sep 1, 2022 EPSS Score
  • Oct 19, 2022 EPSS Score
  • Nov 15, 2022 EPSS Score
  • Dec 7, 2022 EPSS Score
  • Mar 2, 2023 EPSS Score
  • Mar 15, 2023 EPSS Score
  • Jun 20, 2023 EPSS Score
  • Sep 26, 2023 EPSS Score
  • Nov 7, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›