VDB

GCVE-110-MAGEIA-2023-14

GCVE-110-MAGEIA-2023-14
Advisory Published
Vulnetix · Advisory published January 24, 2023
It was discovered that there was a potential cross-site scripting vulnerability in smarty3, a widely-used PHP templating engine. In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user. (CVE-2018-25047)

Affected Products

VendorProductVersionsPlatforms
Mageiakeepass2.53-1.mga8 (unaffected), 0 (affected)
Mageiaphp-smarty0 (affected), 4.2.1-1.mga8 (unaffected), 4.2.1-1.mga8 (unaffected), 0 (affected)

Browse GCVE Records

74,608 records in the GCVE database · Updated July 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›