Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Takaram

#41084de 56,330
7.1CVSS total
Vulnerabilidades · 1
PT-2023-21728
7.1
2023-03-28
Smarty · Smarty · CVE-2023-28447
**Name of the Vulnerable Software and Affected Versions** Smarty versions prior to 3.1.48 Smarty versions prior to 4.3.1 **Description** The issue is related to improper escaping of JavaScript code in the Smarty template engine for PHP. An attacker could exploit this to execute arbitrary JavaScript code in the context of the user's browser session, potentially leading to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user. **Recommendations** To resolve this issue, users are advised to upgrade to either version 3.1.48 or version 4.3.1. For versions prior to 3.1.48, upgrade to version 3.1.48. For versions prior to 4.3.1, upgrade to version 4.3.1.